Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill directs the agent to execute a local Python script with network, file read/write, environment, and shell capabilities, but the skill metadata does not declare any permissions or capability requirements. This creates a transparency and policy-enforcement gap: a host may treat the skill as low-privilege while it can still access secrets, modify local files, and make outbound requests through the bundled runtime.
