Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs users to run local Python commands that can read files, write files, access environment variables, invoke the shell, and send data to a remote API, yet it declares no permissions or capability boundaries. Even though the content says only specified authorized assets are uploaded and names a fixed endpoint, the absence of explicit permission declarations and enforcement increases the risk of unintended file access, secret exposure, or exfiltration if the script behavior differs from the documentation or is modified.
