Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to read local files and invoke a shell-based Python script, but it declares no corresponding permissions. That creates a transparency and policy-enforcement gap: users and the platform may not realize the skill can access repository contents and plan files from the local machine. In this context, the data access is related to the skill’s purpose, which makes it less suspicious than arbitrary file access, but still risky because it touches potentially sensitive source code and work artifacts.
