Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documentation indicates shell execution of a local Python script, but the manifest does not declare corresponding permissions. This creates a transparency and policy gap: users or the platform may not realize the skill can execute code, which increases risk if the script is modified or abused later. In context, the stated functionality does require code execution, so this looks more like an undeclared-capability issue than overtly malicious behavior.
