Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to run a local Python script, inspect local configuration, and modify multiple platform config files, which implies shell execution plus file read/write access. Because these capabilities are not declared in metadata, a caller or host cannot accurately assess the skill's operational risk before use, increasing the chance of unexpected configuration changes or abuse if the skill is invoked in a broader context.
