Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read an environment variable, execute a bundled Python script, and make outbound API requests, but the skill file does not declare corresponding permissions. This mismatch can bypass expected user or platform scrutiny, making the skill more dangerous because it can access credentials and the network despite appearing minimally scoped.
