Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to use shell commands and environment-based API key configuration, but the skill metadata shown in this file does not declare those capabilities explicitly. Hidden or undeclared execution and credential access increase the risk of overprivileged use, reduce auditability, and make it harder for users or policy layers to understand what the skill can actually do.
