Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs users to run local Python commands that read files, write downloaded outputs, use environment variables such as SKILL_PATH, invoke shell execution, and make outbound network requests to an external API, yet the skill declares no corresponding permissions. This creates a trust and review gap: operators may execute a skill with broader capabilities than expected, and unauthorized local files or sensitive data could be exposed to the external service if the script is modified, misused, or later expanded.
