Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
- The skill instructions direct execution of a Node.js CLI that relies on environment-derived agent identity and likely accesses environment variables, yet the skill declares no corresponding permissions or capability disclosure. This creates hidden trust and data-flow risks because an agent may read or depend on sensitive environment state without the user understanding that scope.
