Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes a local Python script and references a local JSON file path, which indicates code/file-read capability despite declaring no permissions. This creates a trust and sandboxing issue: the runtime may permit filesystem access that users and reviewers are not informed about, and direct execution of local scripts increases risk if the script or referenced files are modified or contain unsafe logic.
