Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill directs execution of local Python scripts, reads local audio files, writes JSON output, accesses environment variables for API keys, and sends data over the network, yet it declares no permissions. That mismatch is a real security issue because operators and agent frameworks cannot accurately gate or review the skill's capabilities, increasing the risk of unintended data access or exfiltration.
