Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation instructs users to run local Python scripts and invoke generation/processing commands, which implies shell execution and file access capabilities, but the metadata declares only a binary requirement and no explicit permissions. This mismatch can cause users or platforms to grant more capability than is transparently disclosed, increasing the risk of unintended file access or command execution in environments that rely on declared permissions for trust and isolation.
