Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly instructs the agent to run a local Python script via shell, but the manifest declares no tool restrictions or allowed-tools scope. That mismatch creates an authorization gap: an agent/runtime may permit broader shell execution than the skill actually needs, increasing the blast radius if the skill is abused or if user-controlled paths/arguments are passed unsafely elsewhere.
