Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation clearly describes capabilities to read credential files, write consolidated secrets, modify .gitignore, and invoke shell scripts, but it does not declare any explicit permission model or scope boundaries. That mismatch increases the risk of over-broad execution and makes it harder for users or a platform to enforce least privilege around sensitive filesystem and shell access.
