Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to read candidate/job materials, write files, and invoke a shell command (`python3 ...` / `typst`) but declares no permissions or trust boundaries. This creates an undeclared capability gap: operators may authorize the skill assuming it is passive text guidance, while it can actually access local data and execute tooling, increasing the chance of unintended file access or command execution in sensitive environments.
