Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs users to run a local Python script that reads local files, writes state, uses shell execution, and makes outbound network requests, yet the skill declares no permissions. This mismatch is dangerous because operators may invoke the skill without understanding that it can access local assets and transmit data to an external API, increasing the risk of unintended data exposure or unsafe execution in a higher-trust environment.
