Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill clearly instructs the agent to read user-supplied files, write large project structures, and execute shell/Python commands, yet it declares no permissions. That creates a dangerous transparency gap: a host or reviewer may treat it as low-risk while it can still perform filesystem changes and command execution on arbitrary project data.
