Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill advertises and documents capabilities to read environment configuration, write configuration files, and trigger a shell-based gateway restart, but there is no declared permissions section warning users or the host about those sensitive actions. This is dangerous because users and orchestration systems may invoke the skill expecting a low-risk documentation-style action, while it can modify persistent agent behavior and operational state.
