Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no permissions, yet its documented behavior clearly requires sensitive capabilities including environment variable access, filesystem access, shell execution, and network communication. This mismatch is dangerous because it hides the true execution surface from reviewers and policy enforcement, making it easier for the skill to access secrets such as API tokens and perform external actions without explicit user or platform approval.
