Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes external scripts, reads environment-derived credentials implicitly, and performs file read/write operations, yet it declares no permissions. This under-disclosure is dangerous because a host or reviewer may approve the skill believing it is a simple formatting/archive helper, while it can actually modify workspace state and trigger code paths with access to sensitive host configuration.
