Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents runnable commands and code capabilities that can read environment variables, access files, invoke shell commands, and make network requests, yet it declares no permissions. This creates a transparency and governance gap: a host or reviewer may treat the skill as lower-risk than it is, while the referenced scripts can still handle secrets, local files, and external API calls that may incur cost or expose data.
