Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares no permissions, but its instructions direct the agent to read local reference files, write temporary drafts, and execute local Python scripts. That creates undeclared file and shell capabilities, which can bypass user expectations and platform policy checks and may expose local data or trigger unintended command execution in an agent environment.
