Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares no permissions while its documented behavior requires reading `.env.local`, handling secrets, invoking CLIs, and performing deployments. This mismatch reduces transparency and weakens trust boundaries, making it easier for a user or host system to authorize sensitive behavior without explicit review.
