Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill includes executable examples and operational guidance that use environment variables, local files, shell commands, and network access, but it declares no permissions or capability boundaries. This creates a transparency and governance gap: a host agent or reviewer may treat the skill as low-risk while it can still trigger external API calls, read/write local artifacts, and potentially incur charges or handle sensitive data.
