Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs users to run a local Python script with filesystem, shell, environment, and network access, but it does not declare those capabilities or permissions up front. This is dangerous because users and policy systems cannot accurately assess the trust boundary before execution, increasing the chance of unintended local file access, credential use, or outbound network activity.
