Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs execution of a Python script that performs network access, reads and writes persistent files under the user's home directory, and is invoked from the shell, yet the skill declares no permissions. This creates a trust and review gap: users or platforms may authorize or run the skill without understanding that it can persist credentials and communicate with external services.
