Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs execution of a Python pipeline that uses environment variables, writes files, and performs network access, yet the skill metadata shown does not declare those capabilities or permissions. This is dangerous because an agent or operator may invoke it without understanding that it will reach external sites, scrape content, and create artifacts on disk, reducing informed consent and weakening permission enforcement.
