Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises shell-capable behavior through documented git commands, but it does not declare any permissions or safety boundaries for executing those operations. This can cause an agent or user to invoke repository-affecting commands without an explicit trust/approval model, increasing the risk of unintended command execution in sensitive workspaces.
