Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill invokes local scripts and references environment-backed state, but it does not declare an explicit tool scope or allowed-tools boundary. That increases the chance an agent will run code or access environment-dependent resources without clear authorization controls, especially in systems that rely on metadata for sandboxing decisions.
