Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill documentation describes capabilities to read local files, write configuration and credential backup files in the user's home directory, and execute shell commands, yet no permissions are declared. This creates a transparency and consent gap: an agent may invoke file and shell operations users did not explicitly authorize, increasing the chance of unintended data access or modification.
