Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to run local Python scripts, invoke shell commands, read scan output, and perform network uploads, but the manifest declares no permissions. This creates a trust and review gap: an agent or platform may authorize the skill without surfacing that it can access local data, environment context, and exfiltrate scan-derived information over the network.
