Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly instructs the agent to read local files, invoke a Python script, and send network requests, yet it declares no permissions or user-facing warning about those capabilities. In an agent setting, undeclared file, shell, and network actions reduce transparency and can lead to unexpected exfiltration of local request files, credentials, or payloads to remote endpoints.
