Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the user to run shell commands, create files such as .env, install dependencies, clone repositories, build Docker images, and interact with external network resources, but it does not declare any permissions despite clearly requiring env, file_write, network, and shell capabilities. In an agent execution environment, this mismatch can bypass operator expectations and safety controls, increasing the risk of unintended code execution, secret handling, or filesystem/network side effects.
