Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to use shell commands, read/write local files for configuration, access environment variables for `ARI_API_KEY`, and make network requests, but it does not declare permissions. This creates a real security and governance gap: the runtime may grant capabilities implicitly without clear user visibility or policy enforcement, increasing the risk of secret exposure, unintended external calls, or unauthorized local state changes if the skill is misused or modified.
