Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill describes creating worktrees/subagents and applying or discarding code changes, which implies filesystem access and likely shell execution, but it declares no corresponding permissions or safety boundaries. This is dangerous because the agent may gain effective code-execution and file-modification capability without explicit user awareness, increasing the chance of unintended repository changes or abuse through hidden operational scope.
