Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill embeds executable workflows that use environment variables, local files, shell commands, and network access, yet it declares no permissions or capability boundaries. This is dangerous because users and hosting platforms cannot accurately assess what the skill may access or modify, increasing the risk of unintended file access, secret exposure, or outbound requests to external services.
