Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities that access environment variables, read local files, use the network, and invoke shell commands, but it does not declare any permissions or constraints. This creates a trust gap: an agent may invoke a skill with broader side effects than users or policy expect, increasing the chance of unintended data exposure or command execution.
