Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares no required permissions, yet its content instructs the agent to run Python scripts, access and modify memory files, and create backups, which implies shell, file-read, and file-write capabilities. This mismatch weakens permission transparency and policy enforcement, increasing the chance that a host agent executes sensitive operations without an explicit capability grant or adequate user awareness.
