Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to use shell-capable tools and environment-based credentials, but the metadata shown declares no permissions. That creates a transparency and policy gap: agents or users may invoke a skill believing it is documentation-only when it actually drives command execution and accesses secrets, increasing the chance of unintended command execution or credential exposure.
