Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs use of shell commands and a local script, but it does not declare any explicit tool scope or allowed-tools boundary. That increases risk because an agent may execute shell-capable behavior more broadly than intended, including handling secrets and network access without clear confinement.
