Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation exposes capabilities to read environment variables, read/write files, invoke shell commands, and access the network, but it declares no permissions. That mismatch creates a trust and containment problem: an agent or reviewer may assume the skill is low-privilege while it can fetch remote content, access local mirror paths, and invoke external tools such as Python and ripgrep.
