Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read an arbitrary Markdown path, launch a local HTTP server, open a browser, and then read and write review artifacts, which clearly exercises file read, file write, and network capabilities without declaring them. Undeclared capabilities are dangerous because they bypass least-privilege review and make it harder for operators to understand the skill's trust boundary, especially since the input path can be relative or absolute and the workflow exposes local content over HTTP.
