Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use local scripts and external resources (`scripts/*.py`, reference files, URL enrichment, MediaWiki/Wikidata publishing), which implies file-read and network-capable behavior despite no declared permissions. This mismatch is dangerous because it can enable undeclared data access or outbound requests that users and policy controls are not expecting, especially in a publishing workflow that fetches URLs and can push content to external services.
