Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation describes executing local scripts via shell-like command mappings (`handler.py`, `bookmark.py`) but declares no permissions, creating a capability/permission mismatch. This is dangerous because users and policy layers are not informed that the skill can invoke executable code, reducing transparency and weakening review and containment controls.
