Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to invoke shell commands and operate on local repositories, yet it declares no explicit permissions or capability boundaries. This creates a transparency and policy-enforcement gap: downstream systems or reviewers may treat the skill as lower risk than it is, while it can still trigger file reads and code-modifying command execution.
