Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and demonstrates capabilities that access environment variables, local files, shell commands, and external network services, but it does not declare permissions or boundaries for those actions. This reduces transparency and weakens user consent and sandboxing expectations, which can enable unexpected data access, command execution, or exfiltration if the scripts are invoked in a permissive runtime.
