Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent/user to execute local Python scripts and shell commands and to write multiple output files, yet it declares no permissions. That mismatch is a real security issue because it hides the skill's capability to modify the workspace and invoke external tooling, preventing informed consent and proper sandboxing decisions.
