Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises read-only, dry-run organization behavior but explicitly allows invoking python3 and references reading templates/specs and writing output files, which implies file read, file write, and shell capabilities without any declared permission model. This creates a trust and containment gap: an operator or orchestrator may treat the skill as low-risk while it can access local files and execute a subprocess.
