Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes shell commands via documented `python3` executions but does not declare any permissions, creating a mismatch between advertised and actual capabilities. This can bypass least-privilege controls and make reviewers or execution frameworks underestimate what the skill can do, especially since it also performs outbound network access to a public endpoint.
