Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs agents to execute a bundled Python CLI, read and write repository files, use environment variables, and invoke shell commands, but the manifest shown in SKILL.md does not declare corresponding permissions or capabilities. This creates a trust and sandboxing gap: a host may expose more power to the skill than operators expect, reducing reviewability and increasing the chance of unsafe execution in environments that rely on declared permissions for policy enforcement.
