Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill directs the agent to read and write local files, access environment/config data, and download/run software from the network, yet no explicit permission model is declared. That creates a capability/intent mismatch: an orchestrator or reviewer may underestimate what the skill can do, while the skill can still touch sensitive local state and fetch untrusted binaries. In this context, the risk is elevated because the skill is designed to control arbitrary desktop software and persist reusable templates, which broadens the blast radius of undeclared file and network access.
