Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes a Python script with capabilities consistent with shell execution, filesystem access, environment access, and network use, yet the manifest declares no permissions or trust boundaries. This creates hidden capability risk: a caller may invoke a seemingly simple content-generation skill that can read/write local files, use environment secrets, and make outbound requests without explicit disclosure or consent.
