Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs users to run Python scripts that access environment variables, read/write local files, and make external network calls, yet it declares no corresponding permissions. This creates a transparency and consent problem: users or the hosting platform may invoke the skill without understanding that it can exfiltrate API keys, send pack contents to third-party services, or modify local artifacts such as manifests and eval outputs.
