Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares itself as read-only and documents shell, environment, and network-backed execution paths, but it does not expose an explicit permissions model. That creates a governance gap: a caller or platform may treat the skill as lower risk than it really is, even though it can access credentials from the environment and make authenticated cloud and Kubernetes queries.
