Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions while instructing use of a bundled Python client that can read local files, write/update package files, access environment-held credentials, invoke shell commands, and make network requests. This under-declaration is dangerous because users and hosting agents cannot accurately assess the trust boundary or enforce least privilege before the skill performs sensitive local and remote operations.
