Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly invokes shell and network-capable actions such as committing local changes and pushing to a remote repository, yet it declares no permissions or approval boundary. That makes the automation harder to reason about, increases the chance of silent high-impact actions, and weakens user/operator ability to constrain exfiltration or repository modification.
