Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs users to install dependencies, authenticate with an API key, read and write local configuration files, invoke local Python scripts, and perform network operations against AI Hive, yet no permissions are declared. This creates a trust and transparency gap: an agent or user may grant broader execution than expected, exposing secrets, local files, or enabling unintended network activity without explicit consent boundaries.
