Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to use shell commands and inspect environment-based credential state, but it does not declare corresponding permissions. Undeclared shell/env capabilities weaken reviewability and policy enforcement because operators may trust the manifest while the skill still drives command execution and credential-sensitive flows.
