Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read/write files, invoke Python scripts, use shell commands, reference environment variables, and present generated HTML, but it declares no permissions. This mismatch weakens security review and user consent because the operational capabilities are broader than what the manifest communicates, and the HTML-generation workflow could be abused to write arbitrary files or create active content in the project context.
