Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises and instructs use of shell commands, file access, environment-variable usage, Docker, git, pip, and local server execution, yet declares no permissions. This creates a transparency and consent problem: an agent or reviewer may underestimate the skill's ability to read local files, access env-derived secrets, or execute system commands, increasing the chance of unintended privileged actions.
