Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes shell commands, reads environment variables, downloads remote content, and writes local files including a tfvars file, yet no explicit permission model is declared. This creates a real security gap because an agent may execute high-impact actions without clear sandboxing or user-visible authorization boundaries, increasing the risk of credential misuse, unintended file access, or destructive infrastructure changes.
