Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to invoke local shell commands and read local files such as board images, ASCII board states, configs, and model paths, but it declares no permissions to do so. This creates a capability/permission mismatch that can bypass operator expectations and policy gating, increasing the risk of unintended local file access or command execution if the skill is invoked with attacker-influenced paths or arguments.
