Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill specification describes file reads, file writes, and shell execution without declaring any permissions or clearly constraining what paths and commands may be used. In an agent environment, this creates an unsafe capability gap: a seemingly harmless content-generation skill could access local files, overwrite outputs, or invoke arbitrary scripts if activated.
