Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to read repository state, use shell commands, access environment-provided temporary paths, and create or delete files, but it does not declare permissions for those capabilities. That mismatch is dangerous because a permissionless-looking skill can be approved or reused under false assumptions, while still performing sensitive filesystem and command execution actions including destructive worktree cleanup.
