Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read and write local files and execute shell/Python scripts, but it does not declare permissions or present clear capability boundaries. Because the data handled includes sensitive HR-style notes, stakeholder complaints, and performance evidence, undeclared file and shell access materially increases the risk of unauthorized modification, disclosure, or destructive actions if the skill is invoked in the wrong context or misused.
