Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares and documents capabilities to read environment variables, access the network, write files, and invoke shell-based converters, but no explicit permission model is declared. That creates an overbroad and opaque execution surface: operators or users may trigger a skill that can access secrets and send data externally without clear authorization boundaries.
