Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill performs filesystem, network, and environment-backed operations but does not declare permissions, which weakens reviewability and policy enforcement. In this skill, those capabilities are expected for GitHub auditing, but the undeclared scope could let the agent access or write more than operators realize, especially because it invokes shell scripts, gh commands, and writes approval/workspace files.
