Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to execute local Python scripts, use shell commands, read environment-dependent model paths, and read/write project files, but it does not declare corresponding permissions. This creates a trust and review gap: operators may invoke the skill without realizing it has code-execution and filesystem capabilities, increasing the risk of unintended file access, shell misuse, or environment data exposure.
