Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly advertises live access to Reddit, PullPush, and Arctic Shift and instructs the agent to run networked CLI commands, yet no declared permissions are present. This creates a trust and policy gap: an orchestrator or reviewer may believe the skill is local-only while it can actually exfiltrate prompts or retrieve unvetted remote content, increasing the chance of unintended data exposure or unsafe agent behavior.
