Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill is described as read-only and no-credentials, but it instructs execution of a local Python script and documents report output paths, which implies shell execution, file reads, and file writes without an explicit permission declaration. This mismatch is dangerous because users or policy engines may trust the metadata while the skill can access local files and create artifacts, increasing the chance of over-privileged or unexpectedly executed behavior.
