Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documents capabilities to read local files, write outputs, and send data over the network, but does not declare permissions or clearly bound those actions. In this context, the script can ingest claim documents and forward their contents to a remote LLM endpoint, creating a real risk of unexpected data exposure and policy bypass if operators assume the skill is self-contained and low-privilege.
