Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to read environment variables, write files under a fixed project root, read reference files, and make outbound network requests, but it declares no permissions or guardrails for those capabilities. This creates a capability/permission mismatch that can lead to over-broad execution in environments that rely on declared permissions for policy enforcement or user awareness.
