Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill includes executable code paths and instructs use of environment variables, local file access, shell commands, and networked API calls, but it declares no permissions or capability boundaries. This creates a real security risk because an agent may invoke the skill with broader access than users expect, enabling secret exposure, unintended file operations, or external data exfiltration through the AI-HIVE API workflow.
