Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs use of a Python script that reads Markdown and template files, writes output files, and invokes Pandoc via the shell, but it declares no permissions for file_read, file_write, or shell execution. This creates a trust and policy gap: an agent may perform sensitive filesystem access or command execution without explicit review, and user-controlled paths/templates increase the risk if the implementation is later unsafe.
