Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly describes filesystem reads/writes and shell execution, but it does not declare corresponding permissions. That creates a transparency and policy-enforcement gap: reviewers and runtime controls may underestimate what the skill can do, while the skill can still manipulate local files, run scripts, and access sensitive workspace content. In this context, the capability set is especially risky because the skill operates over agent configuration files and archived traces, which may include secrets, prompts, or sensitive operational data.
