Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes shell scripts and relies on environment variables for API credentials, but it does not declare corresponding permissions. This creates a trust and review gap: an agent or operator may approve the skill without realizing it can execute commands and access secrets, which increases the chance of unintended secret exposure or unsafe command execution.
