Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documents commands that read and write `.env` files, including generating templates and merged outputs, but the metadata declares no permissions. That mismatch can prevent proper policy review and user understanding of what the skill can access or modify, which is especially sensitive because `.env` files commonly contain secrets.
