Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill embeds code and workflow steps that read local files, write configuration/output files, and invoke external commands via subprocess, yet it declares no permissions or user-facing guardrails for those capabilities. This creates a trust and consent gap: users may trigger scraping, file modification, or shell execution without understanding the actual operational scope.
