Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to run shell commands (`git diff ...`) and to read and modify documentation files, but it declares no permissions. This creates a trust and enforcement gap: callers or policy engines may treat the skill as low-risk while it actually requires shell, file read, and file write capabilities, increasing the chance of unintended repository access or modification.
