Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill instructs the agent to run local shell scripts (`./scripts/adopt.sh`, `status.sh`, `interact.sh`, `history.sh`) and to use a GitHub token with `repo` and `workflow` scopes, but the manifest does not declare corresponding permissions. This mismatch is dangerous because it obscures the skill's real capability footprint, increasing the chance that an agent executes code or uses sensitive credentials without explicit user awareness or platform-level gating.
