Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes local Python scripts, reads and writes files, accesses environment variables such as SKILL_PATH and API keys, and communicates with a remote API, yet no explicit permissions are declared. This creates a trust and review gap: users may run a skill with network, shell, and filesystem capabilities they were not clearly warned about, increasing the chance of unsafe execution or secret exposure if the scripts are modified or abused.
