Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes multiple local scripts, reads uploaded content, writes temporary and persisted files, and returns network-hosted Gitea URLs, but it declares no explicit permissions or capability boundaries. That creates a real security governance gap: reviewers and runtime policy engines cannot clearly constrain file, environment, or network access, increasing the chance of over-privileged execution or misuse of sensitive workspace data.
