Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes local Python scripts via shell commands and instructs loading files from the skill directory, which implies effective file-read and shell-execution capabilities, yet it declares no permissions. This mismatch is dangerous because it obscures the skill's actual execution surface from the caller or policy layer, reducing oversight and potentially enabling unintended command, file, or network access through the referenced scripts.
