Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to read bundled files, use live patent/news/literature connectors, and create output artifacts on disk, which implies file-read, file-write, and network behavior without any declared permission model. This is dangerous because users and hosting systems may not have clear consent boundaries for external retrieval and filesystem writes, increasing the risk of unintended data access, exfiltration, or writes outside the expected workspace if the runtime does not enforce strict sandboxing.
