Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation indicates capabilities to read environment variables, read local files, and make network requests, yet no explicit permissions are declared. This creates a governance gap: the skill can access sensitive credentials from environment variables or `.project-info/` and send them over the network without a machine-enforced permission boundary, increasing the blast radius if the implementation is flawed or later modified.
