Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs use of shell execution (`python3 scripts/huawei-cloud.py` / local `hcloud`), environment-variable credentials, and generation of JSON input files, but the metadata shown does not declare corresponding permissions. That mismatch is a real security issue because an agent or platform may grant broader operational capability than reviewers or policy engines can see, undermining informed consent and permission-based isolation for cloud mutations.
