Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to read and write files and execute shell commands (`python3`, `clawhub`) but does not declare permissions or constrain scope. This creates a real capability/intent mismatch: a caller or runtime may not realize the skill can modify the filesystem, package artifacts, or publish releases, which increases the chance of over-privileged or unsafe execution.
