Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill clearly instructs the agent to execute local code, read skill directories, auto-generate files, and optionally run an HTTP service, yet it declares no permissions or safety boundaries. In an agent ecosystem, undeclared filesystem and network capabilities are dangerous because they expand the trust boundary invisibly and can cause operators or higher-level policy engines to authorize behavior they did not expect.
