Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill directs the agent to use shell commands extensively (`revdoku`, `bash`, `curl`, file reads), but no explicit permission boundary is declared. That mismatch is dangerous because a broadly invocable publishing skill can cause real filesystem reads, credential use, and network-side state changes without a clear least-privilege contract.
