Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell commands (`scripts/check_stock.py ...`) and depends on external tooling (`agent-browser`) but declares no permissions. This creates a mismatch between the skill's documented capabilities and its security model, which can lead to unintended command execution in environments that rely on declared permissions for policy enforcement and review.
