Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes shell commands, performs network requests, and writes cookies to disk, yet declares no permissions or capability boundaries. This increases the chance the agent will use the skill in contexts where users did not expect outbound network access or local file writes, weakening review and consent controls.
