Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly invokes a local Python script that reads a user-specified PDF and writes a user-specified Markdown file, which gives it shell execution and file-write capability despite no declared permissions. This is not inherently malicious, but the missing permission declaration reduces transparency and can cause downstream agents or users to invoke a skill with stronger capabilities than expected.
