Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes broad operational capabilities—shell, network access, file read/write, environment access—without declaring permissions or tightly constraining how those capabilities are used. In this context, the skill is instructed to invoke a bundled Python client, upload local files, persist state, and perform updates, which materially increases the attack surface and removes transparency for users and hosts about what privileged actions the skill may take.
