Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to execute a local Python script, install a package with pip, and perform live network access for currency conversion, yet it declares no permissions or capability boundaries. This mismatch can cause the host system or orchestrator to allow code execution and outbound requests without explicit user awareness or policy review, increasing the risk of unintended file/system interaction and network use.
