Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises execution of local package-manager commands and directory-based dependency inspection, which implies shell and file-read capabilities, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a trust and containment gap: an agent may invoke shell/file access without clear least-privilege constraints, increasing the chance of unintended command execution in sensitive directories or against attacker-controlled project files.
