Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes Python scripts, writes to a local SQLite database, and exports CSV files, which clearly require shell execution and file-write capabilities. Failing to declare these permissions weakens transparency and policy enforcement, so an agent or reviewer may authorize the skill without understanding its ability to modify local files.
