Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly relies on environment variables and shell commands, but it does not declare corresponding permissions. Undeclared capabilities reduce transparency and can cause the agent or user to invoke a skill without understanding that it will access local environment data and execute shell-based install/build steps.
