Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents executable commands and operational behaviors that imply access to environment variables, local files, shell execution, and outbound network calls, yet no explicit permission model is declared. That creates a confused-deputy risk: an agent or reviewer may treat the skill as low-privilege while it can actually read/write files, use API keys from the environment, and call external services.
