Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to invoke a local Python script, read reference files, inspect installed skills, and mutate platform configuration files, which implies shell, file read, file write, and environment access. Because these capabilities are not explicitly declared, users and enforcement layers may underestimate the privilege level of the skill, increasing the chance of unsafe approval or execution in sensitive environments.
