Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill documentation describes capabilities that include file read/write, network access, and shell execution, but it does not declare permissions or clearly bound those powers. In an agent ecosystem, this creates a dangerous trust gap: operators may approve or invoke the skill as a governance component while it can also manipulate local files, expose services, and execute commands with little transparency.
