Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and demonstrates shell execution, local file access, environment-variable use via $SKILL_PATH, and outbound network access to a remote API, yet no permissions are explicitly declared. This creates a transparency and governance gap: an agent or reviewer may underestimate the skill's operational reach, increasing the risk of unintended command execution, filesystem access, or data egress when the skill is invoked.
