Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes executable workflows that read environment variables, read and write local files, invoke shell commands, and optionally contact external APIs, yet it declares no permissions. This creates a trust and review gap: users or orchestrators may grant or assume fewer capabilities than the skill actually needs, increasing the chance of unintended file modification, secret exposure, or network egress when the skill is run.
