Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to read and write project files and execute shell commands, but it declares no permissions or trust boundary for those capabilities. That creates a confused-deputy risk where a user may invoke a 'design' skill without realizing it can inspect the repository, launch processes, and modify files, increasing the chance of unintended local impact.
