Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to execute a local Python script, read local Codex session logs, access environment-dependent paths, and optionally write machine-readable output for downstream automation, yet it declares no permissions. This mismatch is dangerous because users and enforcement systems may assume the skill is non-privileged when it actually performs shell execution and local file access, increasing the risk of unintended data exposure from sensitive usage logs and reducing policy visibility.
