Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill exposes code-capable behaviors including environment access, file read/write, network access, and shell-style execution without declaring permissions or clearly constraining their use. This creates a confused-deputy risk where a user or downstream agent may invoke broader local or external actions than expected, including secret exposure, arbitrary file manipulation, or unreviewed outbound requests.
