Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill describes capabilities that require network access, shell execution, environment-variable access, and local file writes, but it does not declare permissions or constrain how those capabilities are used. In a marketplace/payment skill, this is dangerous because the agent may handle wallet identifiers, agent IDs, payment proofs, and local state without explicit sandboxing or user-visible authorization boundaries.
