Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, write credential/token files, and invoke shell commands, yet no explicit permissions are declared. This creates a transparency and least-privilege problem: users may grant or run the skill without understanding that it handles secrets and filesystem state. In a credential-handling skill, missing permission declarations materially increase risk because the behavior is sensitive even if expected for the feature set.
