Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to run local Node.js CLI scripts and references stored credentials, which implies access to environment/config data and outbound network communication, yet no explicit permissions are declared. This creates a transparency and consent gap: an invoking user may believe they are using a simple advisory skill while the skill can access local state and communicate with vendor cloud services.
