Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to use shell commands, read and write local files under work/ and scripts/, persist user policy and activity ledgers, and call external research/data sources, yet no permissions are declared. That mismatch creates hidden capability risk: a reviewer or runtime may underestimate that this skill can access sensitive portfolio data, mutate local state, and produce side effects such as transaction requests or archival writes.
