Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to execute local Python scripts, consume API keys from the environment, write files under outputs/, and call external Gemini endpoints, yet it does not declare corresponding permissions or provide an explicit capability boundary. This creates a trust gap where a caller may treat the skill as low-risk documentation while it actually performs shell, network, environment, and filesystem operations.
