Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises executable workflows that use environment variables, local file access, shell commands, and network calls, but it does not declare any permissions or capability boundaries. This creates a transparency and trust problem: users and hosts may invoke the skill expecting a documentation-only teardown helper while it can actually access sensitive runtime resources and perform billable external actions.
