Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill declares no permissions while instructing the agent to read configuration files, write modified config state, and execute a shell command that restarts the gateway. This hidden capability increases the chance of unauthorized sensitive operations and reduces the effectiveness of permission review and user consent.
