Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises shell-capable dependencies (`curl`, `jq`) but does not declare any explicit tool scope such as `permissions` or `allowed-tools`. That creates an overbroad execution surface where an agent may invoke shell functionality without a clearly constrained policy, increasing the chance of unintended command execution or misuse if the skill implementation evolves or is paired with untrusted input.
