Scope Creep
High
- Confidence
- 95% confidence
- Finding
- The sandbox deployment section instructs the agent to create arbitrary files in a user-specified project directory and run local Docker build/push commands, but these capabilities are not declared in the skill's manifest permissions. This creates a hidden privilege expansion risk: an agent following SKILL.md could modify unrelated local codebases and perform powerful local operations the user did not explicitly authorize through the permission model.
