Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill advertises executable workflows that install packages, run Python, access environment variables, read/write files, and make network requests, yet it declares no permissions. This creates a transparency and governance gap: users or orchestrators may invoke a capability-rich skill without informed consent or policy controls, increasing the risk of unintended data access or external exfiltration through the referenced script.
