Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly relies on sensitive environment variables, local file access for credentials or compose files, and network access to a privileged infrastructure API, yet it declares no explicit permissions or safety boundaries. This creates a capability-transparency gap that can lead to overprivileged execution and makes it easier for an agent or user to invoke powerful actions without understanding the full access being granted.
