Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill is designed to enumerate highly sensitive data sources such as environment variables, memory files, config, and git history, and it invokes a shell command to do so, yet it declares no permissions. That mismatch is dangerous because it conceals the true capability footprint from users and policy systems, reducing informed consent and increasing the chance the skill is activated with broader access than expected.
