Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares itself as a document-formatting optimizer, but its instructions require environment-variable access and network-capable behavior. Even without bundled executable code in this file, directing the agent to use env and network capabilities without declaring them creates hidden behavior and weakens user consent and permission boundaries.
