Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities that require network access, environment variable access, and file reading, but it does not declare any permissions or capability boundaries. This creates a least-privilege and transparency failure: reviewers and runtime policy systems cannot accurately assess or constrain what the skill can access, increasing the risk of unintended data exposure, unauthorized outbound requests, or misuse of secrets from environment variables.
