Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to use shell commands, read local files, and access environment variables, but it does not declare permissions or constraints for those capabilities. This creates hidden execution and data-access scope, making it easier for the skill to read sensitive local material or use secrets like MCP tokens without transparent user consent.
