Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to access environment variables, read local files, write reports, invoke a shell command, and use a model API, but it declares no permissions or trust boundaries. That mismatch is a real security issue because it can cause over-privileged or opaque execution, making sensitive resume data and API secrets accessible without explicit authorization controls or user-visible consent.
