Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation instructs operators to deploy Python and systemd-based automation that performs health checks, restarts services, and writes files, which implies shell and environment interaction despite no declared permissions. This mismatch is dangerous because it can bypass user expectations and review controls, leading to over-privileged deployment or unnoticed execution of operational actions on a host.
