Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read and write local files and execute Python commands, but no explicit permission model is declared in the skill metadata. That creates a real security gap because a caller or orchestrator may invoke a capability-bearing skill without clear guardrails, increasing the risk of unauthorized filesystem changes or shell execution if the skill is triggered unexpectedly or used in a weakly mediated environment.
