Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill describes and exposes functionality that reads workspace files and invokes shell-backed system and git inspection commands, but it does not declare any permissions. This creates a transparency and policy-enforcement gap: consumers may run a skill with broader filesystem and command-execution reach than advertised, increasing the chance of unauthorized data exposure or unsafe execution in sensitive environments.
