Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill explicitly instructs use of shell commands (`curl`, `bash scripts/rank.sh`) but does not declare any tool scope such as `permissions` or `allowed-tools`. This creates an authorization gap where an agent may execute shell/network-capable actions without an explicit least-privilege boundary, increasing the chance of unintended command execution or broader environment access.
