Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises broad operational capabilities—reading environment variables, file access, shell execution, and possible networking—but does not declare permissions or boundaries in the skill metadata. That creates a transparency and trust problem: users or agents may install and auto-run it without understanding the full access it may exercise, especially since it is intended to run on every task.
