Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent/user to execute shell commands, read local reference files, and includes a destructive cleanup command, yet it declares no explicit permissions or capability boundaries. This mismatch is dangerous because it can cause the platform or user to underestimate the skill's operational power and approve execution without proper consent or sandboxing.
