Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs users to run shell commands, read local files, and consume environment variables for MCP tokens, but it does not declare corresponding permissions or trust boundaries. This creates a capability-transparency gap: users or host systems may expose sensitive local files or credentials without an explicit permission model, increasing the risk of token leakage or unintended local access.
