Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to use shell execution, network access, local file handling, and implicit identity/state management, yet no explicit permissions or trust boundaries are declared in the manifest. This creates a confused-deputy risk where a reviewer or runtime may underestimate the skill's real capabilities, especially because it can fetch remote URLs, write local files, and call cloud APIs.
