Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs users to run a Python upload script that uses both shell execution and outbound network access, but the skill declares no permissions or capability boundaries. This creates a transparency and least-privilege problem: an agent or user may invoke code with broader effects than the manifest communicates, including uploading local files and using credentials from a .env file.
