Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill documentation instructs users to run shell commands and invoke a local shell script, but the skill declares no permissions for shell/code execution. This creates a trust and capability mismatch: an agent or user may execute shell-based installation or runtime steps without an explicit permission boundary, increasing the risk of unintended command execution or abuse if the referenced repository or scripts are modified.
