Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill embeds runnable shell and Python commands that use environment variables, local files, network access, and external tooling, yet no explicit permissions are declared. This creates a trust and review gap: a host may expose broader capabilities than users expect, increasing the chance of unintended file access, secret handling, or outbound requests when operators treat the skill as documentation-backed automation.
