Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares no permissions while its documented behavior includes environment access, network connectivity, and writing workflow files. This is dangerous because it hides the real execution surface from reviewers and users, making credential use, data exfiltration, or unintended persistence easier to miss during approval.
