Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documents and encourages use of shell commands and an environment variable containing a credential-bearing MCP endpoint, but it declares no corresponding permissions. That mismatch is a real security issue because an agent or runtime may execute the skill with broader capabilities than reviewers expect, and the URL token can grant CRM access if exposed through logs, prompts, shell history, or subprocess usage.
