Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill declares no permissions, but its documented behavior includes shell execution and file writes via Python invocation, virtualenv creation, package installation, model downloads, and output generation. This is dangerous because it hides meaningful execution and filesystem capabilities from the permission model, preventing users or the platform from making an informed trust decision before the skill runs.
