Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises and instructs use of a Python script that performs network requests and persists watcher state, but the skill file declares no permissions. This creates a capability/permission mismatch that can bypass least-privilege review and lead operators to approve a skill without understanding it can read/write local data and access external URLs.
