Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill advertises no declared permissions/network access, yet the package clearly invokes a Python script and is designed to read workspace inputs and write output files. This creates a trust and review gap: operators may approve or sandbox the skill based on incomplete capability disclosure, while the executor can still access local files and shell out through Python. In this context, hidden file read/write and shell capability are meaningful because the skill processes arbitrary workspace content and can modify repository state.
