Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation declares only a CTS API permission, but the skill clearly instructs users to run a local Python script and the analyzer detected network and shell capabilities. This mismatch is dangerous because operators may approve or invoke the skill without understanding that it can execute code and make external calls, weakening review, consent, and sandboxing assumptions.
