Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs the agent to read project files, create or modify `project.skill.md`, and run validation scripts, which implies file read/write and shell capabilities. If those capabilities are not explicitly declared and constrained, downstream systems or reviewers may underestimate what the skill can do, increasing the chance of unintended file changes or command execution in a repository.
