Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises executable workflows that use environment variables, filesystem access, shell commands, and outbound network calls, but it does not declare permissions or capability boundaries. This creates a confused-deputy risk where a caller or hosting platform may not realize the skill can access local files, invoke commands, or transmit data externally, increasing the chance of unintended secret exposure or unsafe execution.
