Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill instructs use of local scripts, shell commands, and file reads/writes, but it declares no explicit permissions or guardrails for those capabilities. This creates an authorization and transparency gap: an agent may execute code and modify files without the user or platform having a clear, enforceable permission boundary.
