Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read and modify workspace files and execute shell/Python commands, but it does not declare any permissions or capability boundaries. That makes the trust surface opaque: a user or host system may treat the skill as low-privilege while it can actually alter AGENTS.md, install files, and run validators/watchdogs, increasing the risk of unintended filesystem changes or command execution.
