Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly instructs use of shell commands plus file read/write operations against git hooks, SQLite files, and user home-directory config, but it does not declare permissions. That creates a transparency and consent problem: an agent or user may invoke a tool with broader filesystem and command execution effects than expected, including hook installation and data deletion.
