Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to execute a local Python script and write generated output to workspace/reports, which implies shell execution and file-write capability without any declared permissions or constraints. This weakens security review and increases the chance that a broadly invocable skill could be used to perform unintended local actions or process adversarial input through tooling the platform did not explicitly authorize.
