Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises operational commands that read environment variables and local files (for example `LYGO_STACK_ROOT`, registry paths, and `self_check.py` behavior) but does not declare corresponding permissions. That mismatch can cause users or agents to grant trust under incomplete information, and in adversarial scenarios hidden file/environment access can be abused to inspect sensitive local paths or configuration.
