Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read environment variables, invoke a local Python script, and make outbound network requests, yet no declared permissions are present. This creates a governance and transparency gap: an agent may perform sensitive actions without an explicit permission model, making unintended secret access or network exfiltration harder to detect or constrain.
