Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation describes code paths that read environment variables, write local credential files, access the network, and invoke shell commands, yet it declares no explicit permissions. This creates a trust and review gap: users or platforms may authorize the skill under a narrower mental model than its actual capabilities, increasing the risk of credential exposure, unintended file modification, or uncontrolled external requests.
