Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill includes runnable shell commands and scripts that use environment variables, local file paths, networked API access, and file read/write behavior, yet it declares no permissions or capability boundaries. This creates a dangerous mismatch: an orchestrator or reviewer may treat the skill as low-risk while it can actually trigger external requests, process local files, and handle secrets such as API keys.
