Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly describes shell execution, file copying, git clone/push, and cron setup, but it does not declare permissions accordingly. This creates a governance and review gap: an agent or platform may invoke a skill with write and shell capabilities that were not transparently surfaced to the user or policy engine. Because the skill exfiltrates local brain files to a remote repository, undeclared capabilities materially increase risk.
