Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill directs use of shell, network, file read/write, and environment-derived credentials, but it declares no explicit permissions or trust boundaries. That creates an authorization gap: a host agent may run broad CLI/API calls and write reports to disk without a least-privilege contract, increasing the chance of unintended access or data exposure.
