Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares no explicit permissions, yet its instructions include reading local resource files, writing output files, and optionally invoking a shell command via python3. This creates a transparency and policy-enforcement gap: a reviewer or runtime may assume the skill is low-risk while it can still access the filesystem and execute local code.
