Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent to run shell commands and access network-backed services via GitHub/Azure/LLM providers, yet no explicit permission model or scope restrictions are declared. That creates a confused-deputy risk where a user can trigger repo access, syncs, remote API calls, and file modifications without a transparent least-privilege boundary.
