Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs use of shell commands, network access, and environment variables containing sensitive credentials, but it does not declare permissions or boundaries for those capabilities. That gap can cause an agent runtime or reviewer to underestimate the skill’s access, increasing the risk of unintended command execution, credential exposure, or outbound requests to attacker-controlled endpoints if configuration is altered.
