Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs users to run a bundled Python script that reads environment variables, accesses local files, performs outbound network requests, writes downloaded content to disk, and invokes shell/OS integration, yet it declares no permissions or equivalent safety disclosure. This mismatch can cause users or orchestration systems to grant or execute broader capabilities than expected without informed consent, especially because the workflow includes automatic downloads and opening Finder.
