Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to run local Python code and to update local JSON/history files, which implies file read/write capability, but the manifest declares only a required binary and no corresponding permissions. This creates a permission-model mismatch: users or hosting platforms may believe the skill is less capable than it actually is, reducing transparency and weakening security review and consent.
