Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares no permissions, but the documented commands invoke a local Python script that can read environment variables, scan arbitrary files/directories, create a policy file, and potentially inspect workspace content broadly. This mismatch can mislead users and policy engines about the skill's actual capabilities, reducing transparency and weakening least-privilege controls.
