Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to run Node.js scripts that read a local key file and send user-supplied queries to an external service, but no declared permissions are present. This creates a transparency and policy-enforcement gap: networked data exfiltration and local secret use can occur without an explicit permission model, which is especially sensitive here because the returned data may include contact and employee information.
