Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation describes capabilities that require sensitive operations such as reading environment variables, writing API keys to local config, network access, and invoking shell commands, yet no explicit permissions are declared. This creates a transparency and least-privilege problem: users and the platform cannot easily assess or constrain what the skill may access before execution.
