Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes a Python script with an API key in the environment and performs external network activity, but the manifest declares no permissions or capability boundaries. This is dangerous because agents and reviewers cannot accurately assess what sensitive resources the skill can access or exfiltrate, increasing the chance of unintended data disclosure or unsafe execution in higher-privilege environments.
