Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes local Python scripts and external binaries (`bbot`, `nmap`) and writes results to disk, but it declares no permissions for shell execution, file reads, or file writes. This creates a capability/permission mismatch that can bypass user expectations and platform policy controls, especially for a recon tool that performs network scanning and stores outputs.
