Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares required environment variables and executable tools, and it instructs the agent to read local files and submit them to external APIs, but it does not declare explicit permissions for file access, network access, or secret handling. This creates a permission-model mismatch where a host may under-enforce or fail to surface the real data-exfiltration and file-handling behavior to users.
