Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to read local reference files and use local scripts that normalize requests, render inputs, write output files, and perform format conversion, which implies file read, file write, and shell/code-execution capabilities despite no declared permissions. This mismatch is dangerous because it obscures the skill's actual execution surface, preventing policy enforcement and making it easier for a downstream agent to invoke filesystem or script actions without explicit approval boundaries.
