Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation describes capabilities that involve environment-variable access, reading and writing local files, and invoking script-based executors, yet it declares no explicit permissions. That mismatch weakens security review and runtime governance because an agent may use sensitive capabilities such as credential loading from env vars or local connection files without transparent authorization boundaries. In this context, the danger is elevated because the skill handles database credentials and local data sources, so undeclared file/env access can expose secrets or broaden access beyond what users expect.
