Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes a Python script and explicitly documents capabilities such as network access, local file writing, shell execution, environment-variable use, and reading saved temp files, yet the manifest declares no permissions. This creates a trust and policy gap: a host may treat the skill as low-privilege while it can still reach external services and persist data locally, increasing the risk of unintended exfiltration, unsafe file handling, or bypass of operator review.
