Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill invokes shell-capable tooling (`python3 scripts/git_ctrl.py` and the git CLI) but does not declare permissions, which weakens transparency and policy enforcement around command execution. In an agent setting, undisclosed shell capability increases the chance that the skill is enabled or trusted more broadly than intended, especially since git operations can read local repository contents and interact with remotes.
