Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill orchestrates shell commands, reads local env files, performs network access, and writes/commits files, yet it declares no explicit permissions. This creates a hidden trust boundary: an agent or reviewer may approve or invoke the skill without realizing it can access credentials, modify repositories, and send external data over the network.
