Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly requires sensitive capabilities—environment access for credentials, filesystem read/write for token caching, and network access to a cloud API—but does not declare permissions explicitly. This weakens least-privilege controls and user/operator awareness, making it easier for a high-impact device-management skill to run with broader access than expected.
