Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill invokes local file reads/writes and shell-based tooling (`npm install`, `pip install`, and running a Python script) but does not declare any permissions. That is dangerous because users and enforcement layers cannot accurately assess or constrain the skill’s real capabilities, increasing the chance of unexpected file modification or command execution in the host environment.
