Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill invokes a local Python script and a bundled converter capable of shell execution and writing files, yet it declares no permissions or safeguards. In an agent environment, undeclared file-write and shell capabilities reduce transparency and policy enforcement, increasing the chance of unsafe execution on attacker-controlled file paths or unintended filesystem locations.
