Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute local Python scripts, read and write persistent state, and interact with filesystem paths, yet the skill metadata declares no permissions. This creates a trust-boundary mismatch: an orchestrator or reviewer may treat the skill as low-privilege while it actually performs shell execution and filesystem operations, increasing the chance of unintended file access or command execution in sensitive contexts.
