Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly directs access to environment variables, local files, and shell command generation, but no explicit permission model is declared. That creates an authorization and transparency gap: a user may invoke a skill that reads local configuration and constructs authenticated outbound requests without clear disclosure of those capabilities.
