Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute a Python script, read configuration files, inspect local git repositories, and save a report, yet it declares no permissions. This creates a transparency and consent gap: the skill can access environment data, read files, and invoke shell/git over potentially broad portions of the user's filesystem without an explicit permission contract.
