Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill clearly instructs the agent to read local files, write Terraform files, and invoke shell-like commands and an MCP CLI tool, yet it declares no permissions boundary. That mismatch can let a caller or platform assume the skill is passive when it actually has filesystem and command execution capabilities, increasing the chance of unauthorized file access or writes.
