Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use local scripts (`call.py`, `call-node.js`), read a local configuration file containing an `auth_token`, and make outbound network requests, but it does not declare permissions for file access or networking. This creates a transparency and policy-enforcement gap: an agent or platform may invoke sensitive capabilities without users or reviewers having explicit permission metadata to evaluate or constrain them.
