Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to use shell, filesystem, environment, and network capabilities extensively, but no explicit permission model is declared. In a remote-connector skill that can authenticate, discover agents, send messages, and invoke local commands, this creates a large implicit trust boundary and increases the risk of unintended command execution or data exposure if the skill is misused or the implementation diverges from the documented constraints.
