Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill includes executable examples and operational guidance that use environment variables, local file paths, network access, and shell commands, but it declares no permissions or capability boundaries. This creates a confused-deputy risk where an agent may read/write files, access secrets, or call external APIs without explicit user awareness or policy gating, especially because the workflow includes uploading media and polling remote services.
