Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to run a local Python script, read session data from the user's filesystem, and write saved configuration, but it does not declare any permissions. That creates a transparency and policy-enforcement gap: a user or runtime may not realize the skill needs shell, file-read, and file-write access before it executes, increasing the chance of unintended local data access or modification.
