Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to derive and execute a local Python entrypoint and explicitly states use of file path handling, shell execution, and network access, yet no permissions are declared. This creates a capability/permission mismatch that can bypass governance controls, making it harder for a host system or reviewer to understand and restrict what the skill is allowed to do.
