Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill directs the operator to run shell commands, consume environment variables, and make network calls, yet the skill file declares no permissions or equivalent capability boundaries. That creates a confused-deputy risk where a user or platform may treat the skill as low-privilege even though it can stop/start containers, contact external endpoints, and access sensitive configuration from `.env` values.
