Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs users to run shell commands, read and write configuration files under the user's home directory, and launch local services, yet it declares no permissions or trust boundaries. That mismatch can cause users or orchestration systems to grant the skill more access than expected and obscures the real security posture of the skill.
