Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares powerful capabilities through its metadata and instructions (environment access, shelling out to local binaries, reading templates and run artifacts, writing persistent outputs, and cloud fallback) without an explicit permissions model or user-facing constraint boundary. This is dangerous because a caller may invoke what appears to be a simple diagramming skill while it can access secrets, persist artifacts, and make networked requests, increasing the chance of data exposure or unintended side effects.
