Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to execute shell commands (`npm ci`, Playwright install, and Node CLI runs) and write to arbitrary output paths, but it does not declare corresponding permissions. This creates a trust and policy gap: operators may approve or run the skill believing it is low-privilege when it can install dependencies, access environment state, and modify the filesystem.
