Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to use shell execution, file reads/writes, environment variables, and networked services, but the manifest exposes no declared permissions or capability boundaries. This creates a mismatch between what reviewers/users can infer and what the skill actually does, increasing the chance of over-privileged execution and unsafe deployment in environments that rely on manifest declarations for policy.
