Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises and documents execution via `python3` and references reading local resources and writing output, but it does not declare corresponding permissions. This creates a transparency and policy-enforcement gap: a reviewer or runtime may assume the skill is lower risk than it really is, enabling unexpected file access or shell execution in environments that rely on declared permissions.
