Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes significant capabilities—environment access, local file read/write, and network/database operations—without declaring permissions or clearly constraining when they may be used. That creates a confused-deputy risk where a user may invoke powerful side effects, including credential configuration, local artifact persistence, and remote database access, without an explicit trust boundary.
