Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill embeds runnable commands and documents capabilities that use environment variables, local files, network access, and shell execution, but it declares no permissions. This creates a transparency and policy-enforcement gap: a host may invoke or approve the skill without realizing it can read/write files, access secrets such as API keys, and make outbound requests that may incur cost or exfiltrate data.
