Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill documentation instructs use of shell commands, network access, and writing output files, but the skill declares no permissions. This creates a trust and enforcement gap: an agent or reviewer may assume the skill is low-privilege when it actually performs external requests and filesystem writes, increasing the chance of unsafe execution without appropriate sandboxing or user consent.
