Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 76% confidence
- Finding
- The skill instructs users to run shell commands and relies on environment-backed configuration, yet it declares no permissions or equivalent trust boundary information. This creates a transparency and review problem: operators may invoke a skill with execution capabilities they did not expect, increasing the chance of unsafe deployment and privilege misuse.
