Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises and documents file reading and shell-based execution through `python3 scripts/convert.py` and `wkhtmltopdf`, but it does not declare corresponding permissions. Undeclared capabilities reduce transparency and can cause the agent or user to invoke filesystem and subprocess behavior without appropriate review, which is risky for a conversion skill that processes local files and writes outputs.
