Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation advertises and operationalizes a Python CLI that users download and run locally, and the static analyzer detected file read and file write capabilities, but the skill declares no corresponding permissions. This creates a trust and audit gap: installers and security reviewers may believe the skill is non-invasive when it can access or modify local files during validation, scaffolding, or self-test operations.
