Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to use shell execution, read environment variables containing cloud credentials, and read/write local files, but it declares no permissions or capability boundaries. That mismatch is dangerous because downstream systems and reviewers cannot accurately reason about what the skill is allowed to do, increasing the chance of over-privileged execution and unsafe secret/file handling.
