Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 97% confidence
- Finding
- The skill instructs the agent to read files, write state and plan files, and invoke shell commands via python3 and git, but the manifest declares no explicit permissions. That creates a capability/authorization gap: a reviewer or platform may believe the skill is low-risk while it can actually access local data, mutate repository contents, and execute subprocesses.
