Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs the agent to execute shell commands and edit configuration, yet it declares no corresponding permissions. This creates a trust and review gap: downstream systems or users may approve the skill under the false assumption that it is non-executing, while it can invoke local scripts and trigger secret-resolution flows that fetch sensitive credentials.
