Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read files, write persistent local logs, inspect environment variables, and execute a Python CLI, yet no explicit permissions are declared. This creates a capability/consent mismatch: a caller or platform reviewer may believe the skill is low-risk while it can persist user data and invoke shell-backed operations, increasing the chance of unauthorized file access or unintended data retention.
