Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill declares only `allowed-tools: Bash Read`, yet its documented workflow includes shell-driven access to local files, cluster state, and companion scripts that can read sensitive kubeconfig data and invoke external CLIs. This mismatch weakens reviewability and policy enforcement because operators may underestimate the real execution and data-access surface.
