Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documents use of environment variables and local file reads (for DB_* overrides and config.yaml) but does not declare corresponding permissions. Undeclared capabilities reduce transparency and can bypass policy controls, making it easier for an agent to access sensitive configuration or secrets without explicit approval.
