Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to invoke shell commands, read and write local files, access configuration and environment-dependent provider settings, and perform network calls, but it declares no corresponding permissions. This creates a capability/permission mismatch that can bypass user and platform expectations, increasing the risk of unintended command execution, filesystem modification, or outbound connectivity when the skill is used.
