Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill declares only allowed tools but no explicit permissions model despite extensively instructing shell execution, package installation, file edits, network access, and environment-variable handling. This creates a capability/permission mismatch that can lead users or agents to run impactful commands without clear consent boundaries or sandbox expectations.
