Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to use shell commands, network access, environment variables, and file writes, but it does not declare permissions or otherwise surface those capabilities as part of an explicit trust boundary. That creates a real security issue because users or orchestrators may invoke the skill without understanding it can access secrets, persist data, and send data off-host via webhooks or email.
