Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to read environment variables, access local files/directories or ZIPs, and make authenticated network requests, yet it declares no explicit permissions. This creates a trust and review gap: an operator may invoke the skill without realizing it can exfiltrate local prototype contents or secrets to a remote ProtoHub endpoint, especially since the URL can be overridden from configuration.
