Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly instructs use of environment variables and shell execution (`locker` CLI, `curl | bash`) but does not declare permissions. Undeclared privileged capabilities weaken policy enforcement and review because an agent may gain secret-accessing shell/env behavior without explicit authorization boundaries.
