Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read local reference files and invoke a shell command that writes a new repository skeleton, but it does not declare any permissions for file read, file write, or shell access. That mismatch is a real security issue because consumers and policy engines cannot accurately assess or constrain the skill's capabilities, increasing the chance of unintended command execution or filesystem modification.
