Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill includes executable Python that reads an environment variable and writes an HTML file, but no explicit permissions are declared. That creates a capability/expectation gap: users or the platform may treat the skill as data-retrieval-only while it can persist files and interact with runtime environment configuration. In this context the code path is limited to report export, so the risk is not arbitrary RCE, but undeclared file-write capability is still a real security and governance issue.
