Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation instructs users to install and run local Python code, export API keys, use cron, and contact external services, which implies environment, filesystem, and network access, yet no permissions are declared. This is dangerous because operators and policy layers cannot accurately assess or constrain the skill's runtime capabilities, increasing the chance of over-trusting code that can access secrets, modify files, or make outbound requests.
