Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to use shell commands, read and write local files, inspect environment variables, and access external network endpoints, yet no explicit permission model is declared. This creates a broad, implicit trust boundary where an installable skill can perform sensitive actions on the host and user data without transparent scoping or user-visible capability restrictions.
