Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to use network access, shell execution, and local file read/write operations, but it declares no permissions or equivalent trust boundaries. That mismatch is dangerous because users and orchestration layers may not realize the skill can download arbitrary remote content, consume local cookies files, write HTML to disk, and invoke Python scripts, increasing the chance of over-privileged execution or unsafe approval flows.
