Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs users to run shell commands and references a script that can modify live cron jobs with `--heal`, read environment variables, and write state or configuration-related data, but it declares no `permissions` or `allowed-tools` scope. That mismatch weakens least-privilege controls: an agent platform may permit broader shell, file, or environment access than reviewers and users expect, increasing the blast radius if the skill is misused or later modified.
