Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs use of local scripts that read environment variables, access files such as `.env/ges_env.csv`, and make live network requests, yet the skill declares no permissions. This undermines transparency and sandboxing assumptions, making it easier for an agent or user to invoke capabilities with credential, file, and network access without an explicit permission boundary.
