Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill clearly directs the agent to read and write local files and execute shell scripts, yet no permissions are declared. In a wallet-management skill, undeclared shell and filesystem access is especially risky because it can manipulate keystores, secrets, logs, and system state without transparent consent boundaries.
