Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read a local API key file, interact with external ComPDF endpoints, and potentially refresh local reference सामग्री, but it declares no permissions for file access or network use. This mismatch is dangerous because it hides sensitive capabilities from the permission model and user review, increasing the risk of unintended secret access or outbound data transfer without clear consent boundaries.
