Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no explicit permissions while instructing the agent to execute Python scripts, read and write session files, invoke external tooling for document/audio ingestion, and use networked Feishu/Lark and update-check functionality. This creates a hidden capability surface that weakens policy enforcement and user consent, especially because the skill may run in the main agent on channels without per-peer isolation.
