Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 79% confidence
- Finding
- The skill declares runtime requirements for Python and an environment variable carrying a password, and its documented behavior inherently requires network access to iCloud and shell execution of a local script, but it does not explicitly declare these permissions. This creates a transparency and least-privilege problem: an agent or reviewer may underestimate the skill's access to credentials, local execution, and external services.
