Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises executable workflows that use environment variables, local file access, shell utilities, and network calls, but it does not declare permissions or clearly constrain those capabilities. This creates a trust gap: a caller may invoke the skill expecting planning-only behavior while the skill can drive file, network, and shell-adjacent operations that could expose secrets, alter local data, or trigger billable external actions.
