Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read repository files, run shell commands, write ledger artifacts, and potentially edit source or deploy, but it declares no explicit permissions. That mismatch weakens policy enforcement and informed consent because a host may treat the skill as low-privilege while the instructions clearly drive file, environment, and shell-capable behavior.
