Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill describes and instructs use of shell commands, filesystem access, environment-based credential lookup, and networked ASR/TTS/messaging integrations, but it does not declare permissions for those capabilities. This reduces transparency and prevents informed consent or policy enforcement for actions like reading local credential files, invoking external tools, and transmitting data off-platform.
