Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill describes and encourages use of environment variables, local config files, Python scripts, shell commands, and outbound HTTP requests, yet it declares no permissions or trust boundaries. That creates a capability/expectation mismatch: an agent may access network, files, environment secrets, or shell-like execution paths without explicit user awareness or policy gating.
