Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to execute a Python entry script, use the aliyun CLI profile, make networked API calls, write reports to disk, and log metadata. Those are real code-execution capabilities, yet the static finding says no permissions are declared, which creates a dangerous mismatch between apparent and actual power. In a security-analysis skill, this is especially risky because shell, network, environment, and file-write access could expose credentials, exfiltrate cloud data, or operate on the wrong account if the runtime trusts undeclared capabilities.
