Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill documentation invokes a Python script that can install packages, access environment variables, read/write files, use the network, and execute shell commands, yet no permissions are declared. This creates a trust and containment gap: users and platforms cannot accurately assess or sandbox the skill’s actual capabilities, increasing the risk of unintended data access, exfiltration, or filesystem modification when the script runs.
