Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to read and write local files, fetch remote PDFs over the network, and invoke shell commands, yet no permissions are declared. That mismatch weakens policy enforcement and user visibility: a caller may assume the skill is low-privilege when it can actually download untrusted content and execute local tooling against it.
