Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to run local Python scripts, read and write files, access network APIs, and use caching, yet no permissions are explicitly declared. In a medical/genomics context, this creates a serious trust and containment gap: the runtime may perform sensitive data access or exfiltration without transparent user/admin review, especially because genomic data is highly sensitive.
