Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to install packages, execute Python, write output files, inspect environment variables, and construct download links, but it declares no corresponding permissions. This mismatch is dangerous because it hides meaningful execution capabilities from the platform’s permission model and reviewers, increasing the risk of unauthorized file writes, unintended network/package-fetch activity, or misuse of environment-derived secrets in a high-trust financial workflow.
