Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill explicitly instructs the agent to scan directories, write a Python script, and execute it, which implies file read/write capability without any declared permission model or user-facing guardrails. This creates a real security issue because the skill can modify local data and inspect filesystem contents while giving the user no clear notice of that access scope.
