Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs users to run a bundled Python script and invokes external commands (`python`, `codexbar`, shell pipelines, file/stdin input), but it does not declare any tool scope such as `permissions` or `allowed-tools`. That creates a mismatch between documented capabilities and declared restrictions, making it easier for an agent runtime to grant broader-than-intended shell or file access without explicit review.
