Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read local files, invoke a local Python script, and make outbound network requests, but it declares no permissions or trust boundaries. This creates a real security issue because an orchestrating agent may execute shell/network/file operations without explicit user-visible authorization, increasing the risk of unintended local command execution or data access if the skill is misused or later modified.
