Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill clearly instructs use of local shell and file-reading capabilities (`ssh`, `python3`, helper scripts, patch application), but it does not declare an explicit tool scope such as `permissions` or `allowed-tools`. In agents that rely on manifest-level scoping, this can cause the runtime to grant broader-than-intended access or leave reviewers without an enforceable boundary, increasing the risk of command execution beyond the minimum needed for the skill.
