Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use shell execution, read and write local files, access environment variables, and optionally make network requests, but it does not declare permissions. That mismatch weakens user awareness and policy enforcement, especially because the workflow handles sensitive local documents and may read API keys from environment variables.
