Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs file reads, file writes, and shell execution, but it does not declare any permissions or boundaries for those capabilities. This is dangerous because an agent may execute commands and modify repository files without an explicit permission model, reducing transparency and increasing the chance of unintended or over-broad actions.
