Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructions direct the agent to read and write workspace files and invoke Python-based tooling, but the skill declares no permissions. That mismatch can bypass operator expectations and policy controls, making file and environment access occur without explicit review; in a code-executing skill, hidden capabilities materially expand attack surface.
