Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to invoke an inter-session messaging capability (`sessions_send`), which is effectively a communication/network-like action, but no explicit permission model or authorization constraints are declared in the skill. That gap can enable unintended message routing, spoofed-looking internal communications, or abuse of agent-to-agent channels if the runtime does not enforce strict access controls outside the skill.
