Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill declares powerful tool requirements including `exec`, `read`, and `write`, and the static analyzer also detected shell-like capability, but there is no explicit permission model or constraints describing what commands may be run. In an agent environment, undocumented shell access materially increases risk because a user invoking an OSINT skill could unintentionally grant the skill the ability to run arbitrary local commands, access files, or alter the workspace.
