Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell, network, file read/write, and environment-dependent operations through a bundled Python client, yet no permissions are declared to inform or constrain the host. That mismatch is dangerous because it hides a materially broader trust boundary than a user would expect from a storyboard-planning skill, including remote calls, local state changes, and file upload behavior.
