Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read environment variables, invoke a local Python script, and make network requests, but it declares no corresponding permissions. This creates a trust-boundary problem: operators and users are not clearly informed of the skill's effective capabilities, and a future script change could silently expand data access or exfiltration risk under an under-declared manifest.
