Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes a local Python script with capabilities including environment access, file read/write, shell execution, and outbound network access, but it does not declare permissions or clearly bound those capabilities in a machine-enforceable way. Even though the documented workflow appears legitimate, an undeclared-capability skill increases the risk that users or hosts will execute it with broader access than expected, enabling unintended file access, data exfiltration, or misuse of supplied API keys.
