Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises shell and environment-variable based capabilities but does not declare permissions in the manifest. That mismatch weakens policy enforcement and user/agent transparency, making it easier for a skill to execute commands or access secrets without explicit review. In this context, the skill is intended to call external tooling and use API credentials, so undeclared capabilities are a real governance and containment issue.
