Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill clearly instructs the agent to use both shell and network-capable tools (`gh`, `git`, cloning repos, calling the GitHub API), but it does not declare permissions or otherwise constrain those capabilities. In a skill system that relies on declared permissions for review, policy enforcement, or user consent, this creates a real security gap because the skill can fetch remote content and execute local commands without an explicit capability contract.
