Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs the agent to use shell execution, read and write files, access environment variables, and manage local repositories and config files, yet it declares no permissions. That mismatch prevents meaningful sandboxing and user review, especially dangerous here because the same skill can execute live fund-moving DeFi operations and touch wallet/config material stored on disk.
