Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill claims it does not rely on external APIs, but the documentation exposes code execution-related capabilities through validation commands and example imports, while no explicit permissions are declared. This creates a transparency and governance gap: a host may treat the skill as low-risk even though it can read local files or invoke shell commands during testing or execution contexts.
