Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill explicitly instructs the agent to read and write user files under ~/.workbuddy and to invoke shell commands such as cp and python3 scripts/commit_state.py, yet the skill metadata declares no permissions. This creates a hidden capability/permission mismatch: a reviewer or platform may believe the skill is conversational-only, while it actually performs persistent file access and shell execution on user data.
