Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to execute a Python script that uses environment variables, reads and writes local files, and makes outbound network requests, but it does not declare corresponding permissions. That mismatch weakens policy enforcement and informed review, increasing the chance the skill is invoked in environments where its true capabilities are not expected or adequately sandboxed.
