Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documents shell execution, environment-variable access, and outbound network use, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates an authorization gap: a host agent may expose broader capabilities than intended, and reviewers or policy engines cannot reliably constrain execution to the minimum required privileges.
