Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill exposes executable capabilities including environment access, filesystem read/write, shell execution, and network access, but does not declare permissions or clearly bound them. In an agent setting, this increases the chance that the skill can perform sensitive actions such as reading local files, persisting credentials, or making external requests without adequate transparency or policy gating.
