Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes shell commands, reads local configuration, uses network access, and relies on environment/default credential chains, yet it declares no explicit permissions or capability boundaries. This is dangerous because reviewers and policy engines may treat it as lower risk than it is, while the skill can still access cloud identity context, local files such as CLI config, and perform outbound probes.
