Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to read environment variables, invoke local shell commands, and make networked ticket-management requests, but the file declares no permissions model. That creates a capability-transparency gap: users and orchestrators may not realize the skill can inspect auth state, consume tokens, or execute CLI commands on the host, increasing the risk of unintended data exposure or overbroad execution.
