Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 98% confidence
- Finding
- The skill explicitly instructs the agent to run local Python commands, read multiple local data stores, write large numbers of files into an Obsidian vault, inspect environment variables, and optionally perform git operations. Those are privileged behaviors, but the skill declares no permissions boundary or consent model, which increases the chance an agent platform will grant broad access implicitly or without clear user review. In this context the capability set is integral to the skill, but the undeclared scope is still a real security issue because it processes highly sensitive local memory and can stage or publish it.
