Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly performs sensitive operations—reading and writing local authentication files, invoking shell commands, and managing tokens—but it does not declare explicit permissions beyond metadata requirements. This creates a permission-model gap: users or registries may not get a clear, enforceable warning that the skill can modify auth state and propagate credentials into other agent stores. In context, the functionality is intentionally sensitive rather than covert, but the missing formal permission declaration still increases the risk of accidental credential exposure or unauthorized token rewrites.
