Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly instructs the agent to perform network access to the arXiv API and write downloaded PDFs into a local `arxiv/` directory, but it declares no permissions. That mismatch can bypass user or platform expectations about what the skill is allowed to do, reducing transparency and making filesystem and network side effects easier to trigger without adequate review.
