Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read local files, write output HTML, and fetch remote resources such as images and maps, but it declares no permissions. That mismatch can cause the agent or user to grant broader access implicitly than expected and creates SSRF/data-exfiltration risk if attacker-controlled URLs are supplied in the JSON inputs.
