Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to execute a local Python script via shell, relies on a local virtual environment, and references sensitive local assets including an encryption key path. Yet the skill declares no permissions. This mismatch is dangerous because it can cause an agent or platform to perform shell, file, and environment access without transparent user approval or proper sandboxing, increasing the risk of unauthorized local data access or command execution.
