Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to run local Python scripts, read and write files under /tmp, and interact with external Git-based sources, but the frontmatter does not declare any permissions or capability boundaries. This creates a mismatch between documented behavior and runtime power, which can lead to over-privileged execution, weak reviewability, and accidental abuse of file, environment, or network access paths.
