Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to use shell scripts, environment variables, local state files, and multiple network endpoints, but it declares no permissions or trust boundaries. This creates a real security risk because the host or reviewer cannot accurately constrain execution, network egress, or secret access, and the skill explicitly handles connector tokens, device identifiers, and browser-automation flows.
