Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation instructs the agent to invoke local Python scripts, read and write repository artifacts, and operate on arbitrary repo paths, which implies shell, file read, and file write capabilities; it may also process external CVE/manifests, suggesting network-capable workflows. Because these capabilities are not explicitly declared, users and policy systems cannot accurately scope or review what the skill can do, increasing the risk of unintended command execution or data access.
