Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs reading conversation history, writing summary artifacts, and invoking a Python script from the shell, yet it declares no permissions or equivalent capability boundaries. That mismatch is dangerous because it hides the skill's real access needs from operators and increases the chance of unauthorized file access, unintended overwrites, or execution in environments that rely on declared permissions for trust decisions.
