Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to run shell scripts, inspect local files, modify workspace state, and potentially perform networked provider probing, yet it declares no permissions. This creates a dangerous mismatch between the apparent trust boundary and the actual operational capability, making it easier for the skill to be invoked with far more authority than a reviewer or platform policy might expect.
