Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to use shell, file read/write, environment inspection, and network-adjacent repository operations such as `git clone` and running local Python scripts, yet no explicit permissions are declared. This creates a capability/permission mismatch: a caller or reviewer may assume the skill is low-privilege while it actually drives high-impact actions on the workspace and potentially on fetched repositories, increasing the risk of unintended code execution, data exposure, or unsafe file modification.
