Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs the agent to run Promptfoo CLI workflows that can write files (for example `init`, `generate`, red-team setup/report flows) and access the network, but the skill declares no permissions or constraints for those capabilities. This creates a mismatch between advertised safety boundaries and actual behavior, which can lead to unexpected file modification, outbound requests, or execution of external tooling without explicit authorization.
