Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to perform network access to valuesider.com and local file operations (saving fetched content to temp files and reading them for parsing), but the manifest does not declare any corresponding permissions. This creates a trust and enforcement gap: an agent/runtime may execute capabilities users and reviewers cannot see in the declared metadata, increasing the risk of unintended data access or network exfiltration if the skill is modified or reused in a different context.
