Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to read local reference files and invoke local Python scripts, which are code-capable actions, but it declares no permissions. This creates a governance and containment gap: reviewers and runtime policy may underestimate the skill's access to files, shell execution, and network-backed queries, increasing the risk of unintended data access or command execution if supporting scripts or inputs are compromised.
