Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read local files or attachments, invoke shell commands, and make network requests, but it does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass review expectations and lead to unintended access to local data or external services if the skill is invoked with attacker-controlled inputs.
