Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation instructs the agent to use shell commands and environment variables such as exporting LYGO_STACK_ROOT and running multiple Python scripts, but it does not declare corresponding permissions. This creates a mismatch between the skill’s stated security posture and its actual capabilities, which can lead to unexpected command execution or environment access if the hosting platform relies on declared permissions for policy enforcement.
