Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs use of shell commands (`gh`, `git`, `find`, `grep`, `python3`) and mentions writing outputs like reports, but it does not declare any `permissions` or `allowed-tools` scope. This creates a capability/authorization mismatch: an agent may invoke broader shell or file-write access than a reviewer expects, increasing the risk of unintended command execution, repository modification, or data exposure when the skill is run in a permissive environment.
