Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill instructs the agent to run local scripts, edit files, and package artifacts, which implies shell, file read/write, and possibly network-capable execution, yet no permissions are explicitly declared. That creates an authorization and transparency gap: a caller may invoke a skill with broader operational capability than its metadata suggests, increasing the chance of unsafe execution or misuse.
