Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill performs sensitive operations including shell execution, network access, environment-variable use, and file writes, but does not declare corresponding permissions. This creates a governance and transparency gap: callers may invoke a skill with broader capabilities than expected, increasing the risk of unintended data access, outbound transmission, or command execution without explicit review.
