Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to perform network access, write files to /tmp and a workspace path, and send output externally, but it declares no permissions or trust boundaries. This creates a consent and sandboxing gap: users and the platform cannot accurately assess or constrain what the skill will access, store, or exfiltrate.
