Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to read and write local files and execute shell scripts, yet no permissions are declared. That mismatch undermines user and platform trust boundaries because the skill can handle sensitive wallet material, modify state files, and run commands without transparent capability scoping.
