Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no permissions while its documented behavior clearly requires access to environment variables, local files, and outbound network calls. This creates a transparency and consent problem: an orchestrator or user may invoke the skill without understanding that it can read credentials from disk and contact remote services. In a security-sensitive agent ecosystem, hidden capabilities materially increase risk even if the capability is part of the intended workflow.
