Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs use of environment variables, filesystem access, background execution, and shell commands, but it does not declare any permissions or capability boundaries. This creates an authorization and review gap: operators may approve or run a skill without understanding that it can access secrets, read/write local media, and launch persistent processes.
