Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill instructs the agent to read files and invoke a shell script (`python scripts/static_audit.py`) but does not declare corresponding permissions. This creates a capability/permission mismatch that can lead to unintended file access or command execution if the platform relies on declared permissions for review, sandboxing, or user trust.
