Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs use of environment variables, network access, filesystem reads/writes, and shell tooling, yet no corresponding permissions are declared. This creates a transparency and sandboxing gap: a caller may invoke the skill without realizing it can access secrets, write local state, contact external services, and run local tools.
