Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read local files and execute shell scripts (`detect.sh`, `validate-content.sh`, `write.sh`, `restore.sh`, `verify.sh`, `test.sh`) but does not declare permissions for those capabilities. This creates a governance gap: a harness may permit actions users or reviewers did not expect, especially because the skill can modify AGENTS.md/CLAUDE.md and related local files.
