Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises and requires access to environment variables, local files, network endpoints, and shell execution, yet it declares no explicit permissions. That mismatch weakens user consent and review because the skill can scan directories, read configuration from ~/.nex-skillmon/.env, contact external APIs, and invoke setup.sh without a clear permission model. In a monitoring skill that inventories other installed skills, this broad access is especially sensitive because it can expose metadata, secrets, and local system state across the whole skill ecosystem.
