Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to perform network access, read and write files, inspect environment variables, and execute shell commands, yet it declares no explicit permissions boundary. That mismatch is dangerous because a host may expose these capabilities implicitly, allowing broader-than-expected data access or command execution from untrusted inputs such as PoB XML, character codes, or downloaded build data.
