Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation instructs users to run a remote Python script directly from a URL and states that events auto-stream to an external service, which implies network access and likely local data access without any declared permissions. This creates a transparency and consent gap: users may install or run the skill expecting normal visualization behavior while unintentionally granting a remote component access to run data, prompts, tool outputs, or local files processed by the agent.
