Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs the agent to read repository files, inspect Git state, run a local Python inventory script, and potentially modify files when implementing changes, but it does not declare corresponding permissions. This creates a capability/permission mismatch: a host may load the skill under the assumption it is low-privilege while the instructions encourage shell, filesystem, and environment access, increasing the risk of over-broad execution or policy bypass.
