Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares itself as a read-only IAM query tool but instructs execution of shell commands, reads environment credentials, uses network access, and performs package/environment setup without any declared permission boundaries. This creates an opaque trust boundary where a user may invoke code with access to secrets and the network without an explicit capability declaration, increasing the chance of credential exposure or unexpected command execution.
