Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent to use shell commands and make outbound network requests, but it declares only environment-variable requirements and no explicit permissions model. This mismatch can cause the skill to be granted more capability than reviewers or policy systems expect, increasing the risk of unintended command execution or data exfiltration through HTTP calls.
