Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill directs the agent to execute Python that can read environment-derived credentials, access files, make network requests, and run shell-like actions through cloud APIs, yet it declares no permissions or guardrails. That mismatch is dangerous because users and the hosting platform are not given an accurate capability boundary for a skill that can create billable infrastructure and execute arbitrary scripts.
