Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation instructs users to run Python scripts that read project files, write output to `.anatomy.md`, and invoke shell commands, but the skill declares no permissions. This creates a transparency and policy gap: a user or agent may treat the skill as lower risk than it is, while it actually has broad filesystem and command-execution capabilities.
