Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill explicitly instructs the agent to read reference files, execute reusable scripts, write large numbers of generated assets, and invoke shell-capable tooling such as Edge headless rendering and Pillow-based processing, yet no explicit permission model or user-facing authorization boundary is declared. In an agent ecosystem, this mismatch is dangerous because a seemingly content-only skill can cause file-system changes and command execution without clear consent or sandbox constraints, increasing the risk of unintended writes, data exposure, or abuse of shell execution paths.
