Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to execute local shell commands (`codexbar`, `python`) and read local files/stdin, but it declares no permissions to reflect those capabilities. This mismatch can bypass least-privilege expectations and cause the skill to access local cost logs or arbitrary input files without transparent permission gating, increasing the chance of unintended data exposure or unsafe command execution in an agent environment.
