Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation instructs running a bundled Python script that performs network access to user-supplied URLs and can write results to arbitrary output paths, yet the skill declares no permissions. This mismatch is a real security issue because it hides the true capability surface from the agent/user, reducing informed consent and increasing the chance of unsafe use of network and filesystem operations.
