Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and enables access to environment variables and networked behavior without declaring equivalent permissions or clearly surfacing that trust boundary to the user. Undeclared capabilities are dangerous because they reduce transparency and can hide sensitive data access, outbound connections, or policy-bypassing behavior behind a seemingly simple generation skill.
