Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to read local files, write outputs, and execute shell commands, but it does not declare permissions or safety boundaries for those capabilities. In an agent environment, undeclared shell and filesystem access can lead to overbroad execution, accidental processing of unintended files, or command execution against attacker-controlled paths and filenames.
