Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent to execute a Python script that reads input, writes output files, and fetches remote content from Hacker News and linked third-party sites, yet the skill metadata does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: agents or review systems may underestimate the skill's access to the filesystem and network, increasing the risk of unintended data exposure, unsafe fetching, or execution in overly permissive contexts.
