Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs file reads/writes and shell command execution, but the manifest does not declare any permissions or capability boundaries. That mismatch is dangerous because a host agent may grant broader implicit access than users expect, especially when handling kubeconfigs, API tokens, and cluster-management commands.
