Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to execute Python scripts, read local documents, write reports/mindmaps, and call external APIs, which are code-capable behaviors involving file read, file write, and network access. Because these capabilities are not explicitly declared via a permissions model, users and the platform may not have clear visibility or enforcement over what the skill can access or transmit, increasing the risk of unintended local data exposure or exfiltration from the knowledge-base workspace.
