Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill documentation indicates capabilities to read local files, invoke Python from the shell, and send data over the network, but it does not declare permissions explicitly. In an agent environment, this weakens transparency and policy enforcement, making it easier for sensitive local payment screenshots to be accessed and exfiltrated without clear user-facing capability boundaries.
