Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation exposes environment-based credential use and installation/usage patterns, but it does not declare permissions for access to environment variables or shell-related capability despite clearly depending on them. In an agent ecosystem, undeclared capabilities weaken transparency and policy enforcement, making it easier for a skill to access sensitive secrets or invoke installation flows without informed approval.
