Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises substantial capabilities—environment access, file read/write, network access, and shell usage—yet declares no permissions. For a secrets-management skill, these capabilities are highly sensitive because they enable discovery, import, exposure, and transmission of credentials without clear user consent or sandboxing expectations.
