Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs the agent to execute Python scripts that read and write local files, call the networked arXiv API, and invoke shell commands, yet it declares no permissions or capability boundaries. That mismatch can cause downstream systems or users to invoke the skill without understanding its operational reach, increasing the risk of unintended file modification, data exposure, or network activity.
