Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions while explicitly instructing the agent to execute shell commands, read environment variables for cloud credentials, and make network calls to Huawei APIs. That creates a capability transparency gap: users and reviewers may believe the skill is low-risk/read-only, while it can still access secrets, install dependencies, and reach external services. In a credentialed cloud environment, this hidden capability materially increases the chance of unintended secret exposure or unreviewed code execution.
