Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to execute a Python script that performs network access to Binance and can write output files, but the manifest declares no corresponding permissions. This creates a capability/permission mismatch that can bypass operator expectations and weakens security review, because a seemingly low-privilege skill can still trigger outbound requests and local file creation.
