Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes capabilities to read/write local files, access environment variables, invoke shell tools, and send data to external APIs, but it does not declare permissions accordingly. This creates a transparency and consent problem: callers may invoke the skill without understanding that local content and secrets such as STEP_API_KEY can be accessed and that files may be modified or transmitted off-host.
