Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill invokes `bash scripts/kube-medic.sh` and operates against Kubernetes APIs via `kubectl`, which implies network-capable access to cluster endpoints, yet no permissions are declared in the manifest. This creates a transparency and governance gap: users and hosting platforms may treat the skill as lower-risk than it is, even though it can query sensitive cluster state and metadata over the network.
