Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises a simple briefing function, but static analysis indicates shell execution and file-write capabilities without any declared permissions. In an agent environment, undeclared privileged behaviors reduce transparency and can let the skill access local state or persist data in ways the user did not meaningfully authorize.
