Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to derive and execute a local `run.py`, optionally read sibling `sub-skills/.../SKILL.md` files, and call external HTTPS endpoints, which together imply shell execution, file reads, and network access despite no declared permissions. This creates a trust and containment gap: operators reviewing only declared permissions may not realize the skill can execute code and reach the network, increasing the chance of unintended command execution or data exfiltration if the implementation or sub-skills are compromised.
