Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs execution of Python scripts that use network, filesystem, environment inspection, and shell-adjacent capabilities, but it does not declare corresponding permissions in metadata. This creates a transparency and policy-enforcement gap: an agent or marketplace may not warn users appropriately before the skill downloads content, writes files, or invokes local tooling.
