Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill invokes a local Python script with capabilities that include network access, shell execution, environment-variable use, and file read/write, yet no explicit permissions are declared. This creates a transparency and consent gap: an agent or user may run the skill without understanding that it can open browser pages, write credentials to disk, upload local images, and contact external services.
