Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to run local Python scripts, read arbitrary local PDF paths, write multiple output artifacts, and invoke shell commands, yet it declares no permissions. This creates a capability-transparency gap: a host environment or user may authorize the skill under false assumptions, increasing the chance of unintended file access or command execution.
