Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and instructs use of capabilities including environment variables, local credential storage, shell execution, and network access, yet does not declare any permissions or trust boundaries. That creates a transparency and consent problem: users may invoke a skill that can read/write sensitive files and transmit credentials without an explicit permissions model, increasing the chance of credential mishandling or unintended data exposure.
