Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill declares no explicit permissions while instructing the agent to use environment variables, browser/CDP access, and networked backend calls. This weakens permission transparency and reviewability, making it easier for a user or platform to underestimate the skill’s real access to authenticated internal data and state-changing operations.
