Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly performs sensitive operations including reading environment variables for API credentials, reading and writing user configuration and subscription files, invoking shell commands, and making network requests to a third-party logistics API, yet no explicit permissions are declared. This creates a trust and review gap: the runtime or a human reviewer cannot easily understand or constrain the skill’s actual capabilities, increasing the risk of unintended data exposure or overbroad execution if the skill is installed or modified.
