Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill advertises file reading, file writing, and shell execution behaviors but does not declare permissions or safety boundaries. That creates a trust and review gap: users and the platform may invoke a capability-rich skill without clear consent, and the generated workflow could lead to writing files or suggesting shell commands based on repository contents.
