Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to generate tokens, write files, launch a network listener, and expose it publicly, yet it declares no permissions or equivalent user-facing authorization boundaries. That mismatch hides sensitive capabilities from operators and increases the chance the agent will perform risky filesystem and network actions without informed consent, especially given the health-data context.
