Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read files and invoke a shell command (`python scripts/static_audit.py`) but does not declare any permissions or safety boundaries. This creates a transparency and control gap: callers may not realize the skill can access local files or execute commands, which increases the risk of unintended file exposure or command execution in sensitive environments.
