Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to run multiple shell scripts and access a local secret (`~/secrets/moltmarkets-api-key`), but it declares no permissions or capability boundaries. This creates an authorization gap where a caller may trigger shell-based actions and secret-backed API operations without the skill clearly advertising or constraining those powers.
