Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes broad capabilities including shell execution, network access, environment-variable use, and file read/write, but it does not declare permissions or safety boundaries. In an agent setting, this can cause the runtime to grant more trust than warranted, increasing the chance of unauthorized API actions, local file access, or secret handling without user awareness.
