Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to access environment variables, make outbound network requests, and execute shell commands, but it does not declare corresponding permissions. That mismatch weakens policy enforcement and informed consent, because a caller may invoke a skill that can exfiltrate secrets or run local commands without those capabilities being explicitly surfaced.
