Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to perform sensitive operations including writing credential files, downloading remote packs, invoking shell scripts, and making authenticated network calls, yet no explicit permission model is declared. That mismatch is dangerous because a host or reviewer cannot reliably constrain execution, and the skill handles API secrets plus software installation/update flows that could modify the local environment.
