Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill exposes shell execution behavior through documented Python CLI commands and package installation steps, but it declares no permissions or trust boundary information. That mismatch can cause an agent or user to invoke local commands, install packages, or run scripts without informed consent, increasing the risk of unintended code execution and supply-chain exposure.
