Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to use local Python scripts, shell commands, environment variables, and read/write operations under a user directory, but it declares no permissions or capability boundaries. That mismatch is a real security issue because it can cause the agent runtime or reviewers to underestimate what the skill can access or modify, especially since it handles health notes, photos, and reminder data on disk.
