Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly instructs use of sensitive capabilities including credential access, local file read/write, and outbound network calls, but no declared permissions are provided. This creates a governance gap: the agent may be granted more effective power than users or reviewers are warned about, especially because the workflow includes publishing and credential handling.
