Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no formal permissions, yet the content clearly describes capabilities to read credentials from environment variables and local files, write token/trash state to disk, execute shell commands, and make authenticated network requests to a remote service. This creates a misleading trust boundary for users and host systems, because the skill can access sensitive secrets and perform real remote actions without an explicit machine-readable permission declaration.
