Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises executable scripts, an environment variable, and an external model route, which implies shell, env, and network capabilities, but it does not declare permissions or warn about those capabilities. This creates a transparency and governance gap: an agent or reviewer may treat the skill as lower risk than it is, increasing the chance of unintended credential access or external data transmission.
