Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill clearly instructs the agent to read local reference files, inspect and modify agent configuration, access environment variables such as AGENTMEMORY_SECRET, and communicate with a local or remote AgentMemory service, but it does not declare any permissions for those capabilities. This creates a permission-transparency gap: a user or platform may treat the skill as lower risk than it really is, increasing the chance of unintended file access, network calls, or secret exposure during execution.
