Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill directs the agent to use a CLI that performs network operations and accesses credentials via environment/config, but the skill metadata does not declare corresponding permissions. This can undermine platform trust and informed consent because users and orchestrators cannot accurately assess what external access the skill requires before use.
