Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill directs the agent to use shell, network, environment-variable, and local file-write capabilities, including saving API keys locally and exporting reports/files, but it declares no permissions or equivalent trust boundary to the user. This creates a real security issue because the agent can perform sensitive side effects and handle secrets without an explicit, least-privilege permission model or clear user-visible capability declaration.
