Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to read MEMORY.md and execute Python/Docker shell commands, yet it declares no explicit permissions. That mismatch weakens policy enforcement and user awareness, making it easier for a high-impact operation like container recreation to run without clear consent boundaries. In this context, shell access is especially sensitive because apply mode can stop, remove, and recreate containers.
