Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to perform outbound network access to fetch lottery data and to write files in multiple export formats, but no permissions are declared. This creates a capability/permission mismatch that can bypass user and platform expectations, making data exfiltration or unauthorized file creation harder to govern and audit.
