Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to use environment-derived configuration such as GITEA_URL and to invoke local scripts that manage repositories, permissions, and system control data, implying network and environment access. When those capabilities are not explicitly declared, operators and policy systems cannot accurately review or constrain what the skill can do, increasing the risk of over-privileged execution and unsafe repository or permission changes.
