Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises executable code paths that can access environment variables, read/write local files, invoke shell commands, and make network requests, yet it declares no permissions or capability boundaries. This is dangerous because users and host systems cannot make an informed trust decision, and the combination of shell, filesystem, network, and env access could expose secrets or enable unintended system-side actions if the skill is run in an agent environment.
