Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to run shell commands and write exported conversation data to files, but it declares no permissions. That creates a transparency and policy-enforcement gap: a reviewer or runtime may underestimate the skill's capabilities while it can still persist sensitive chat history to disk and invoke local tooling.
