Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs execution of local Python scripts, package installation, file access, environment-variable use, and outbound network calls, yet it declares no permissions or capability boundaries. This creates a transparency and policy-enforcement gap: an agent or reviewer cannot reliably assess or constrain what the skill is allowed to do, increasing the risk of unexpected shell execution, data access, or exfiltration via the referenced API.
