Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs the agent to read and write local files and access external networks, but it does not declare or constrain those capabilities. Undeclared capability use weakens policy enforcement and user awareness, increasing the chance of unintended data access, overwrites, or outbound requests beyond what the user expects.
