Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly requires sensitive environment variables, shell execution, and read/write access to local files, yet it declares no permissions. This creates a trust and review gap: users or platforms may approve the skill without understanding that it can access credentials, persist data, launch background processes, and modify cron-managed state. In a booking skill handling account credentials and reservation logs, undeclared capabilities materially increase security risk.
