Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises executable workflows that use environment variables, local file access, shell commands, and network operations, but it declares no permissions. This creates a transparency and consent problem: a user or host system may invoke a skill that can read/write files, use API keys, and perform external requests without an explicit permission model, increasing the chance of unintended data exposure or unsafe execution.
