Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill explicitly requires Read, Write, Bash, plus external tools like clawhub and curl, but does not declare permissions in a machine-readable way. This creates a transparency and consent gap: an agent may invoke file, shell, and network-capable actions without clear least-privilege boundaries, increasing the chance of unintended data exposure or command execution during publishing workflows.
