Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to run local scripts, read uploaded PDFs, write output files, and invoke shell commands like `bash setup.sh`, but it declares no permissions or trust boundaries. That mismatch is dangerous because users and hosting platforms cannot accurately reason about what filesystem and command execution capabilities the skill requires, increasing the risk of unexpected code execution or file access.
