Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates use of environment variables, shell scripts, and network calls, but no permissions are declared. That creates a transparency and sandboxing problem because a caller may invoke a skill with broader capabilities than expected, including outbound network access and credential handling.
