Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to use shell commands, read files, and inspect environment/project state, but it does not declare corresponding permissions or capability expectations. This creates a transparency and policy-enforcement gap: operators may approve or invoke the skill without realizing it can access local files and execute commands, increasing the chance of unintended data exposure or unsafe command execution in a sensitive repository.
