Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill’s documented behavior explicitly involves reading environment variables, inspecting files and permissions, and invoking a Python script, which implies access to env, file_read, shell, and possibly network-dependent checks. Because these capabilities are not declared in permissions metadata, operators cannot accurately assess or constrain what the skill can access, creating a real transparency and least-privilege issue even if the stated purpose is legitimate self-diagnostics.
