Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises executable shell-based behavior via `python3 oversight.py ...` and operational capabilities like killing sessions, but it declares no permissions. This creates a trust and review gap: consumers may invoke a skill with process-management and file-writing effects without explicit authorization boundaries or visibility into what it can access or modify.
