Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to run local shell commands that read from the repository, write output files, invoke Python scripts, inspect git refs, and optionally call external tools. Because these capabilities are present but not explicitly declared in permissions, a caller or hosting platform may underestimate the skill's access level, increasing the risk of unintended file access, repository data exposure, or unsafe command execution in sensitive environments.
