Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to invoke local Python scripts, read reference files, access environment-controlled behavior, and write local tracking logs, yet it declares no permissions. This creates a capability/permission mismatch that can bypass least-privilege controls, reduce auditability, and allow unintended file or shell access if the skill is enabled in a broader runtime than expected.
