Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares no explicit permissions, yet its manifest and documentation indicate use of `subprocess`, `python`, shell commands, and file-based content input. This creates a capability/permission mismatch that can mislead reviewers and downstream policy enforcement, increasing the risk of unintended file access or command execution through a formatting skill that appears low-risk.
