Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to install packages, execute a Python script, fetch remote content from WeChat, and write Markdown and image files, but it does not declare any permissions for network, shell, or file-write behavior. This mismatch is dangerous because a caller or reviewer may treat the skill as lower-privilege than it really is, reducing oversight around package installation, outbound requests, and filesystem changes.
