Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill declares executable capabilities and data access patterns (Python CLI use, reading input files, writing reports/charts, and likely environment access through the runtime) without an explicit permissions model. This can cause the host agent to invoke file and execution behaviors that users did not clearly authorize, increasing the chance of unintended data exposure or modification.
