Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to read environment variables, access local files, and execute shell commands, but it does not declare permissions or scope limits for those capabilities. That creates a real least-privilege and transparency problem: an agent may perform filesystem or shell actions the user did not explicitly approve, increasing the chance of unintended file access, command misuse, or abuse if downstream inputs are adversarial.
