Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute shell commands and read local reference files, but it does not declare corresponding permissions. This creates a trust and policy gap: the platform or reviewer cannot reliably understand the skill's required capabilities, and an agent may be induced to access local files or invoke CLI tools without explicit approval boundaries.
