Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill advertises itself as a research claim checker, but it explicitly allows shell execution via python3 and implies file input/output capabilities without declaring corresponding permissions. This creates a trust and review gap: a user or orchestrator may treat the skill as low-risk text analysis while it can actually read files, write outputs, and invoke local code.
