Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares powerful tools (Read, Bash, WebFetch) and instructs use of environment variables, shell scripts, and a managed external service, but the metadata does not clearly declare the effective permissions/capabilities. This creates a trust and review gap: operators may enable the skill without realizing it can access secrets, execute shell commands, and transmit data over the network.
