Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the user/agent to run install, status, and uninstall shell scripts and describes behavior that reads and writes local state such as archives, session rotation data, and scheduled tasks, yet no explicit permissions are declared. This creates a trust and consent gap: the skill can perform file system operations with operational impact without transparent permission signaling, which is especially relevant because it manages persistent session data and task installation.
