Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises executable behavior that reads files, accesses environment variables, uses the network, and invokes shell commands, but it declares no permissions. That creates a trust and review gap: operators cannot accurately assess what the skill can access, and a scheduler or agent may run it with broader authority than users expect.
