Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to execute a Python script from the shell, but the skill metadata does not declare any permissions for shell or code execution. This creates a capability mismatch: a reviewer or runtime may treat the skill as lower-risk than it actually is, while the script invocation could expose command execution pathways or unexpected side effects if the environment permits it.
