Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill performs privileged actions including reading environment variables, reading and writing project files, invoking shell commands, and making network requests to Pexels, but it declares no permissions. That mismatch is dangerous because users or the execution framework may authorize the skill under incomplete assumptions, while the skill can still access secrets like PEXELS_API_KEY and modify repository state and output artifacts.
