Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill exposes powerful capabilities including shell execution, network access, remote file read/write, and access to environment/config data, but declares no permissions or equivalent guardrails. In a user-invocable remote server administration skill, this creates a significant trust and safety gap because agents may invoke destructive or sensitive operations without explicit consent boundaries or policy enforcement.
