Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises a local plotting workflow but the detected capabilities include network access without any declared permission boundary. Undeclared network/file-read behavior expands the trust surface and can enable unexpected data exfiltration, remote data fetching, or privacy-sensitive reads when the skill is invoked in broader agent workflows.
