Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates use of environment variables, shell scripts, and network access, but no permissions are declared. This creates a transparency and consent problem: users may invoke a skill expecting simple local behavior while it actually reads secrets and communicates externally. In agent ecosystems, undeclared capabilities materially increase risk because they can bypass user expectations and policy controls.
