Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to read environment configuration, execute a local Python script via shell, access the network API, and handle local files/images, yet it declares no permissions. This creates a transparency and policy gap: users and the runtime may not understand the skill's real capabilities, increasing the chance of unauthorized command execution or data handling without informed consent.
