Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs the agent to run a local shell command and read from user-specified code directories, but it declares no permissions. That mismatch is dangerous because it can lead to unreviewed access to local repositories and metadata, and users may trigger file/system access without clear consent or sandboxing expectations.
