Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documents access to environment variables, network endpoints, and local debug commands that imply file interaction, but it does not declare any permissions or capability boundaries. This is dangerous because an agent or reviewer cannot accurately assess what sensitive resources the skill may access, increasing the chance of unintended secret exposure or unauthorized local/network actions.
