Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent/user to execute a local Python deployment script that reads environment variables, copies files into the user's WorkBuddy plugin directory, and modifies marketplace.json, but it does not declare any permissions for environment access or file read/write. This creates a trust and consent gap: the skill can cause local filesystem changes and use environment-derived paths without explicit permission metadata, increasing the risk of unauthorized or unexpected installation behavior if the bundled script or assets are modified or malicious.
