Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares no explicit permissions, yet its content indicates capabilities to read local resources, write output files, and invoke `python3`, which creates a gap between the trust signal presented to users and the actual power the skill may exercise. Even though the stated use is defensive red-teaming, undeclared file and shell capability increases the chance of unintended local data exposure or execution in environments that rely on manifest permissions for enforcement or user consent.
