Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes shell commands, reads local files, and consumes environment-based configuration, but does not declare any permissions or trust boundaries. This creates hidden capability exposure: an agent or reviewer may assume the skill is metadata-only while it can access local documents, configuration, and execute CLI actions that modify persistent state.
