Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises executable workflows that use environment variables, local file access, shell commands, and network calls, but it declares no permissions. This creates an authorization gap: a host or reviewer may underestimate the skill’s capabilities, increasing the risk of unintended data access, secret exposure, or external requests when the skill is invoked.
