Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to read reference files, invoke a Python CLI, access environment variables for secrets, and write ledger/audit data, yet no permissions are declared. This creates a capability/expectation mismatch: the platform or user may treat the skill as low-privilege while it is designed to perform shell execution, file I/O, and secret consumption, increasing the risk of unintended code execution and sensitive data exposure.
