Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises and instructs use of local scripts that read repositories, generate outputs, and invoke Python from the shell, but the metadata does not declare corresponding permissions. This creates a capability/permission mismatch that can bypass user expectations and platform controls, especially because the skill operates on arbitrary repository paths and can write report artifacts.
