Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs the agent to perform sensitive operations including reading secrets/config files, writing secret material, making network requests, and executing shell scripts, yet it does not declare corresponding permissions. This weakens user awareness and consent, making it easier for an agent to perform impactful actions without transparent permission gating.
