Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to execute local commands, read source notes, write derived outputs, and probe host tooling, yet the skill declares no explicit permissions. This mismatch weakens security review and user consent because an operator may assume the skill is passive while it actually has meaningful file, environment, and possible network-relevant capabilities through invoked binaries and host CLIs.
