Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly instructs the agent to execute local Python scripts and use shell access, but it declares no permissions. This creates a trust and governance gap: a reviewer or runtime may underestimate the skill's capabilities, and users may invoke it without realizing it can read system state and execute commands.
