Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill orchestrates shell commands, reads and writes local files under /tmp, and accesses network-backed sources such as Gitea repositories, yet it declares no explicit permissions or capability boundaries. This creates a real security governance gap: reviewers and runtime policy engines cannot reliably enforce least privilege, and the skill handles untrusted repository URLs, zip uploads, and callback values that increase the risk from overbroad implicit access.
