Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read local files, potentially modify template content, and execute shell scripts that use privileged external credentials for Feishu and GitHub, yet no explicit permissions are declared. This creates a real safety gap because the runtime may grant capabilities implicitly, making it harder to constrain or audit what the skill can access and execute.
