Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to invoke a Python script via the shell and write an MP3 to a fixed workspace path, but it declares no permissions for shell execution or file writing. This creates a trust and containment gap: reviewers and policy engines may not realize the skill can execute commands and create files, increasing the chance of unsafe invocation or inadequate sandboxing.
