Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to read local files and access network resources, but it declares no permissions or trust boundary information. That mismatch can lead to overbroad execution in environments where users or reviewers are not clearly informed that local PDF paths, folders, and external URLs will be accessed, increasing the risk of unintended data exposure or SSRF-like behavior if arbitrary paths/URLs are accepted.
