Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises executable behavior (`python3 .../detect.py`) and hardware auto-detection that necessarily implies local file/system inspection and likely shell access, but the manifest declares no permissions. This creates a transparency and consent gap: a user or platform may invoke a skill that reads local system state or runs commands without an explicit permission contract.
