Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute shell commands, read scripts, and write local Markdown files, yet those capabilities are not explicitly declared in the skill metadata. This creates a hidden-permissions problem: reviewers and policy layers may underestimate what the skill can do, while the skill also writes persistent artifacts and invokes local tooling that could expose workspace data or alter local files.
