Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes Python scripts, shell commands, network fetches, and writes files under the user's home directory, yet it declares no explicit permissions or trust boundaries. This creates a capability mismatch that can cause agents or users to execute file and shell operations without clear disclosure or policy gating.
