Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the agent to read user-provided files, write course outputs, and execute a local shell verification script, but it does not declare those permissions in a machine-readable way. That creates a transparency and policy-enforcement gap: a host may allow the skill to appear less privileged than it actually is, increasing the risk of unintended file access or command execution.
