Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill exposes powerful execution capabilities (shell, file read/write, environment access, MCP) while the finding indicates permissions are not explicitly declared in a dedicated permissions model. In a security-sensitive agent environment, undeclared capabilities reduce transparency and policy enforceability, making it easier for a triggered skill to perform unintended local actions or invoke cloud-affecting commands without clear governance.
