Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read from local workspace paths and execute Python commands through PowerShell, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization gap where a caller or hosting framework may permit broader file and shell access than intended, increasing the risk of unintended command execution or access to sensitive local data.
