Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read user-specified directories, write output files to preset locations, and invoke shell commands, yet it declares no permissions. That creates a capability/consent mismatch: users and the host system are not clearly informed that broad filesystem and command execution actions may occur, increasing the risk of unintended file access, overwrites, or execution of unsafe command arguments.
