Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly directs the agent to read files, write output artifacts, and execute shell/Python commands, yet no permissions are declared. That mismatch weakens reviewability and consent boundaries because a host may treat the skill as less privileged than it actually is. In a skill centered on broad filesystem scanning, undeclared capabilities materially increase the risk of overreach.
