Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs users to run a Python orchestrator that reads and writes files under a target skill and state directory, invokes multiple subordinate scripts, and may execute shell/CLI-driven evaluation flows, yet it declares no permissions metadata. In an orchestration skill that can apply changes, retry automatically, and coordinate end-to-end execution, missing capability declarations materially weakens review and containment because users and policy systems are not warned about its real operational reach.
