Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs use of local scripts that can read files, write files, package artifacts, and invoke validation/packaging tooling, which implies file_read, file_write, and likely shell/process execution capabilities. Because these capabilities are present but not declared, users and policy enforcement layers may not realize the skill can modify the workspace or execute commands, creating a transparency and least-privilege problem rather than clear malicious behavior.
