Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes local Python scripts, reads the user's Chrome bookmarks file, and uses a shell-launched browser open action, but it declares no explicit permissions for file access, environment use, or shell execution. This creates a capability/consent mismatch: users and policy systems may treat the skill as less privileged than it actually is, increasing the risk of unexpected local data access or command execution pathways.
