Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares only Bash and Read, but its documented behavior and configuration indicate access to environment variables and file writing via exported paths and a JSON pipeline tracker. This mismatch can cause an agent or user to grant or rely on capabilities that were not transparently declared, weakening sandboxing and auditability and potentially enabling unauthorized persistence or data modification.
