Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly invokes local Python scripts that fetch stock and market data, implying network access and executable code behavior, yet no permissions are declared. This creates a transparency and policy-enforcement gap: an agent may run code with broader capabilities than a user expects, reducing oversight and increasing the chance of unintended data access or unsafe execution.
