Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill invokes a Python helper script that reads and writes a local database and exports ICS files, yet the manifest declares no permissions. That mismatch weakens security review and policy enforcement because consumers may trust the skill to be non-privileged while it actually has shell execution, filesystem access, and potentially network-capable Python available.
