Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill describes capabilities to scan the filesystem, read credential files, write a consolidated .env, modify .gitignore, and invoke shell scripts, but it does not declare explicit permissions or bounds for those actions. That mismatch is dangerous because a host agent may grant broad implicit access, allowing sensitive file discovery and modification without transparent user consent or enforcement of least privilege.
