Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to run shell commands and use environment secrets such as `QIRA_API_KEY`, but it declares no permissions. This creates a permission-model mismatch: an agent or platform may invoke the skill without surfacing to users that it can execute commands or access sensitive environment state, increasing the risk of unintended command execution or secret exposure.
