Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes a local Python script that supports authentication, status polling, file inputs, and API-key handling, which implies shell, network, file, and environment access without any declared permission boundary. This is dangerous because an agent may execute the skill with broader capabilities than the user expects, enabling outbound data transfer and local file access during handling of potentially sensitive customer comments, product assets, and credentials.
