Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill documentation advertises shell execution and file-reading behavior through a CLI, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where an agent may invoke broader local file access or shell capabilities than a reviewer expects, especially because `--policy-file` allows reading arbitrary paths, including from other workspaces.
