Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly requires `python3` and describes a tool that reads and writes a local JSON state file and is invoked as a shell command, but it declares no corresponding permissions. That mismatch is a real security issue because callers and policy engines may assume the skill is less capable than it actually is, leading to unintended file access or execution in environments that rely on manifest metadata for trust decisions.
