Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent/user to execute local shell commands (`uv run`, `python3`, `pip3 install`) but does not declare corresponding permissions. This creates a trust and enforcement gap: an agent platform may treat the skill as low-privilege while the documented workflow still drives code execution, package installation, and browser-opening behavior on the host.
