Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill declares no tools or permissions, yet its instructions direct the agent to execute a shell command (`python3 ...`) and imply script-based processing. This mismatch is dangerous because it can bypass governance expectations around what the skill is allowed to do, leading to unauthorized command execution or filesystem interaction if an agent trusts the prose over the metadata.
