Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares itself as a read-only query tool but instructs the agent to execute local shell commands, read environment variables, and make outbound network calls without any explicit permission declaration. This expands the effective trust boundary and can lead to unintended command execution, credential exposure risk, or network activity in environments that rely on declared permissions for policy enforcement.
