Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation describes capabilities that access environment variables, perform network requests, and read/write local files, but no permissions are declared. This creates a transparency and consent gap: a caller may invoke the skill expecting a simple content query while the implementation can access secrets and modify local state. In agent environments, undeclared capabilities materially increase risk because policy enforcement and user review may not account for them.
