Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to perform sensitive actions including shell execution, reading and writing repository files, using network-backed source fetches, and accessing external MCP/Zotero tooling, yet it declares no explicit permissions or capability boundaries. This mismatch can cause the runtime or reviewer to underestimate the skill’s effective power, increasing the risk of unintended file modification, data exposure, or unsafe tool use when the skill is invoked.
