Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to execute local Python scripts, write output files, and optionally connect to remote SSH hosts or Kubernetes pods, but the skill declares no permissions despite requiring shell, file read/write, environment access, and network capabilities. This mismatch is dangerous because it can cause the skill to operate with undeclared authority, reducing transparency and making policy enforcement or user consent harder.
