Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes Python scripts that access environment variables, local files, and remote APIs, but it does not declare explicit permissions for those capabilities. This weakens transparency and sandboxing because a caller may not realize the skill can read/write credential files and perform networked side effects such as billing, account actions, and error reporting.
