Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use shell commands, read environment variables, and access local files, but it does not declare permissions or narrowly constrain when those capabilities should be used. This creates a mismatch between apparent trust boundaries and actual behavior, increasing the risk of unintended local file access, token exposure, or command execution in clients that rely on permission declarations for enforcement or user review.
