Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill embeds executable shell/Python workflows that use environment variables, local file paths, networked API calls, and file read/write behavior, but it declares no corresponding permissions or trust boundaries. This can cause the host agent or user to invoke code with broader access than expected, increasing the risk of unintended local file access, secret exposure, or external requests without informed consent.
