Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises use of a local Python script to process CSVs and potentially produce transformed output, which implies file read/write capability, but it does not declare any permissions or equivalent safety boundary in the manifest. This creates a transparency and governance gap: an agent or reviewer may underestimate the skill's access to local data, increasing the chance of unintended file access or modification when handling user-provided datasets.
