Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill describes use of environment variables, shell commands, OAuth flows, and persistent scripts, but the manifest does not declare corresponding permissions or capabilities. This creates a transparency and consent gap: a user may invoke the skill without realizing it can access secrets, execute local commands, and install automation, increasing the chance of over-privileged or surprising behavior.
