Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill reads local files, uses environment-provided credentials, invokes shell/Python, and transmits data to an external service, yet declares no permissions. That mismatch removes an important trust boundary for users and agents, making silent exfiltration of sensitive binaries or proprietary samples possible during what appears to be a local analysis workflow.
