Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to read and write workspace files, invoke shell commands, and publish to an external service, but it declares no permissions or user-consent boundaries. That creates a capability mismatch where a user may trigger actions with broader filesystem, command execution, and network effects than expected, increasing the chance of unintended modification or exfiltration.
