Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill declares command-line execution, reads input files, optionally writes output files, and makes outbound network calls to an external model endpoint, yet no explicit permissions are declared. This creates a governance and sandboxing gap: operators cannot reliably understand or restrict what the skill can access, and in a medical-data context that increases the risk of unintended PHI exposure or overly broad runtime privileges.
