Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises and instructs shell-based operations (git, node, cron, gh) but does not declare corresponding permissions or clearly constrain execution scope. This creates a trust gap where an agent may perform filesystem, process, and network-affecting actions without transparent permission signaling to the user.
