Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation instructs the agent to invoke local shell commands and a Python script, and the workflow includes logging and plan regeneration behaviors that imply file writes, yet the manifest declares no permissions. This mismatch is dangerous because it can bypass user and platform expectations about what the skill is allowed to do, increasing the risk of unauthorized command execution or filesystem modification if the runtime honors the instructions.
