Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill requests and uses sensitive capabilities—environment secret access, local file writes, and outbound network access—but does not declare explicit permissions. Even though the document repeatedly says the tool is read-only and local, it instructs the agent to read an API key from `.env`, call remote NxVET endpoints, and write report/config/state files, which creates a mismatch between declared and actual capability use. This increases the risk of over-privileged or insufficiently reviewed execution in systems that rely on declared permissions for policy enforcement.
