Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill includes shell-based automation examples and operational behavior that performs external API calls, but it declares no explicit tool scope or allowed-tools boundary. In an agent environment, this weakens least-privilege controls and can let the skill be invoked with broader execution capability than users expect.
