Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use shell, network, file read/write, and environment-variable inputs, but it declares no explicit permissions or capability boundaries. That mismatch is dangerous because it obscures the skill's real execution surface, making it harder for a runtime or reviewer to enforce least privilege and increasing the risk of unintended command execution, network egress, or filesystem access.
