Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs use of environment variables, local files, network requests, and shell commands, yet it does not declare permissions for those capabilities. This creates a trust and containment gap: a host may expose sensitive execution capabilities without clear consent boundaries, increasing the risk of unintended API calls, file access, or command execution if the skill or its supporting scripts are modified or abused.
