Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly instructs the agent to read bundled files and optionally run a local Python script, which implies file-read and potentially file-write/code-execution capabilities despite no declared permissions. This creates a transparency and policy gap: the orchestrator or reviewer may treat the skill as lower risk than it actually is, increasing the chance that local resources are accessed without appropriate gating or user awareness.
