Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to perform network retrieval from OpenReview and to create and validate files via Python scripts, but it declares no permissions or capability boundaries. This mismatch is dangerous because users or hosting systems may assume the skill is passive/document-only, while it actually drives network access and local file writes, increasing the chance of unintended data access, unreviewed outbound requests, or unsafe artifact generation.
