Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill describes capabilities that read environment variables, read/write local files, invoke shell commands, and make network requests, but it does not declare permissions or clearly constrain those operations. In an agent ecosystem, this reduces transparency and weakens consent boundaries, increasing the risk that the skill accesses local secrets, modifies files, or performs network actions beyond what a user expects.
