Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes local scripts, reads environment variables for Notion credentials, and reads/writes files, but no explicit permission model is declared. That creates an authorization gap: a runner may grant broader capabilities than reviewers expect, increasing the chance of unintended file or credential access. The danger is moderated by the skill's repeated constraints around secure config and explicit confirmations, but the undeclared capability surface is still real.
