Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill advertises executable commands that read and write local files and invoke Python via the shell, but the metadata does not declare any permissions or capability boundaries. That mismatch is dangerous because an agent or reviewer may treat the skill as lower-risk than it really is, while the documented workflows operate on arbitrary file paths and shell-invoked scripts.
