Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 81% confidence
- Finding
- The skill documents executable commands that use environment variables, local file paths, shell execution, network access, and local file modification, but it declares no permissions. This creates a trust and review gap: operators may invoke capabilities with security impact without explicit consent boundaries, making accidental secret exposure, unsafe file handling, or unintended outbound requests more likely.
