Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly directs the agent to export environment variables, invoke shell commands, and write multiple local files, yet it declares no permissions or equivalent warning/consent boundary. This creates a trust gap: users and hosts may not realize the skill can persist data locally and handle credentials, increasing the chance of unintended exposure or misuse.
