Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs users to use environment variables, write output files, and make arbitrary network requests via scraping/crawling, but it does not declare any permissions. This creates a transparency and governance gap: an agent or user may invoke capabilities with security and privacy implications without explicit permission scoping, especially given the ability to fetch attacker-controlled URLs and save retrieved content locally.
