Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill has material capabilities beyond a passive check: it uses environment secrets, performs network egress, and invokes shell/subprocess operations, yet no explicit permission declaration is present. That gap increases the chance an operator or automation framework will run it with insufficient understanding that it can restart infrastructure and send data externally, which is a real security and availability risk.
