Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to read arbitrary project files, write a Security.md report, invoke a local Python script via shell, and generate network-capable PoC code, yet it declares no permissions or safety boundaries. This creates a transparency and authorization gap: users and hosting systems are not clearly informed that the skill can modify files and execute tooling, increasing the risk of unintended filesystem changes or command execution.
