Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill only declares `allowed-tools: Bash` but its documented workflow clearly instructs the agent to read user-supplied markdown files, write converted output files, and execute shell commands that can install packages and run Python scripts. This permission mismatch weakens transparency and policy enforcement because the skill's effective capabilities exceed what is explicitly declared, increasing the chance of unintended file access, file creation, or package installation during execution.
