Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to read arbitrary memory directories and execute shell commands (`python3 ...`, optionally `qmd update`) but does not declare corresponding permissions. That mismatch is a real security issue because it hides the skill's operational capabilities from permission review and could lead to unexpected filesystem access or command execution when the skill is invoked.
