Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill documentation exposes capabilities to read environment state, invoke shell-accessible commands, and interact with IPC without declaring corresponding permissions or guardrails. In an agent setting, this creates a transparency and policy-bypass risk: callers may treat the skill as low-risk while it can execute impactful local actions such as spawning processes or reloading compositor configuration.
