Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill embeds executable workflows that use environment variables, filesystem access, shell commands, and network calls, but it does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: a host may invoke the skill without understanding it can read/write local files, access API keys, upload media, or call external services, increasing the chance of unintended data exposure or unauthorized actions.
