Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation describes network access to Ensembl and UniProt plus file writes for cache and output generation, but no corresponding permissions are declared. This creates a trust and containment gap: an agent or user may run a skill believing it is low-privilege when it can make outbound requests and write files, which can enable unintended data egress, filesystem modification, or policy bypass in restricted environments.
