Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly describes capabilities to read plaintext private keys, write durable auth artifacts, make network requests, and invoke shell commands for dependency installation and script execution, yet no declared permissions are present. This creates a real trust and sandboxing problem because an agent or platform may authorize the skill without clearly surfacing that it can access sensitive local secrets and persist long-lived credentials.
