Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill exposes the `exec` tool and explicitly instructs the agent to invoke a local Python CLI that reads remote Feishu links, which effectively grants undeclared network/file-access behavior through code execution. This is dangerous because reviewers and policy systems may underestimate the skill's real capabilities, and any prompt or document-controlled input flowing into that CLI could trigger unintended external access or broader execution paths.
