Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to execute a local Python launcher script and optionally pass a user-supplied file path, which implies shell/process execution and file access capabilities. However, the skill declares no permissions, so the runtime trust boundary is unclear and users or reviewers may not realize it can execute code and open local files.
