Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs use of local file parsing and output generation scripts, and it also supports fetching job descriptions from URLs via the requests dependency, which implies file read, file write, and network access. However, the manifest declares no permissions or equivalent capability disclosures, creating a mismatch that can lead to over-privileged or non-transparent execution against sensitive resume data and arbitrary remote resources.
