Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill declares `sensitive_access: false` and `critical_write: false`, yet its documented behavior includes shell execution, file reads/writes, and likely environment access via Python scripts. This mismatch can cause the host or user to under-estimate the skill's privileges, making unsafe execution or approval more likely.
