Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill documentation describes shell execution, network access, and environment-variable credential use, but no explicit permissions are declared. This creates a transparency and policy-enforcement gap: a reviewer or runtime may underestimate the skill’s actual authority, especially because it can use cloud credentials and make external requests. In a deployment skill with billing and infrastructure impact, undeclared capabilities are more dangerous than in a read-only utility.
