Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read bundled files and optionally run a local Python script, which implies file-read capability and potential file-write side effects, yet no permissions are declared. This creates a trust and containment gap: a host may allow behavior the user did not clearly consent to, and the skill’s broad UI/code scope increases the chance those capabilities are exercised during normal use.
