Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises only documentation-level behavior in SKILL.md, but the associated implementation apparently reads environment variables and performs file reads/writes without declaring permissions. In an agent ecosystem, undeclared capabilities weaken operator trust and policy enforcement because a seemingly harmless context-preprocessor can access workspace data and persist logs, increasing the chance of unintended data exposure or unauthorized state changes.
