Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 72% confidence
- Finding
- The skill advertises executable behavior that relies on environment/configuration and server startup, but it does not declare permissions or clearly scope those capabilities. In an agent setting, hidden capability requirements reduce transparency and can lead to the skill being granted broader execution context than users expect.
