Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no permissions, yet the content explicitly authorizes use of `python3` and references reading templates/specs and writing output files. This mismatch can cause the platform or reviewer to underestimate the skill's real capabilities, making shell execution and file access less visible to users and increasing the risk of misuse or unsafe invocation paths.
