Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes file reads and shell execution without declaring corresponding permissions, which weakens the platform's ability to warn, sandbox, or obtain informed consent. In this skill's context, those capabilities are used for reference loading and PDF export, so the risk is operational overreach rather than obviously malicious behavior, but undeclared code-capable actions can still enable unintended file access or command execution.
