Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the operator to run a bootstrap script that reads from the current skill directory and writes multiple files into a target repository, including scripts, hooks, settings, and AGENTS.md content. Those are code-capable behaviors, but the skill declares no permissions, which weakens reviewability and can cause users or enforcement systems to authorize powerful file and shell operations without explicit disclosure.
