Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill clearly describes operations that read environment variables, modify local files, patch gateway configuration, restart services, and interact with Discord over the network, yet it declares no explicit permissions or safety boundary. This creates hidden capability risk because an invoking agent or user may not realize the skill can make persistent system and external-service changes.
