Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to perform network research, read local files, and write run artifacts via a Python ledger script, but it declares no permissions. This creates a capability/permission mismatch that can bypass user expectations and platform policy enforcement, especially because the skill explicitly encourages broad retrieval from untrusted sources and local files.
