Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill advertises and demonstrates shell execution, file input/output, opening local HTML, and invoking an external CLI, but does not declare any permissions for those capabilities. This creates a transparency and policy-enforcement gap: users or orchestrators may approve the skill assuming it is low-risk text summarization, while it can read local files, write artifacts, and execute commands against locally available tools.
