Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises executable workflows that use environment variables, filesystem access, network calls, and shell-based tooling, yet it declares no permissions or equivalent capability boundary. This creates a confused-deputy risk where a user or host may invoke code with broader privileges than reviewers expect, increasing the chance of secret exposure, arbitrary file access, or unintended external requests.
