Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documents and instructs execution of a local Python script that can invoke shell execution, read environment-dependent state, and write files (for example `calibrate.json` and `checkin_result.png`), yet no permissions are declared. That creates a transparency and policy gap: an agent or reviewer may treat the skill as lower risk than it really is, while it actually automates desktop actions and persists files on disk.
