Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill documentation describes Python scripts that use environment data, file input, and networked API access, but the skill declares no permissions or trust boundaries. This creates a capability-transparency problem: users and reviewers may not realize the skill can read local files, access JWT-derived context, and modify/publish remote agent configurations, increasing the risk of misuse or overprivileged execution.
