Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs use of shell and file/database reads (`sqlite3`, `hermes`, local DB paths, helper scripts) but does not declare any explicit tool scope or allowed-tools boundary. That creates an authorization gap where an agent may invoke broader shell/file capabilities than the skill actually needs, increasing the chance of unintended local data access or command execution beyond session-title maintenance.
