Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, invoke shell commands, and access local files, but it does not declare permissions or present clear consent boundaries. In practice this can lead to unexpected access to sensitive API keys and execution of local setup scripts, increasing the risk of secret exposure or unintended command execution when the skill is triggered.
