Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill documentation invokes shell execution (`./scripts/search.sh` and `curl`) but does not declare corresponding permissions. This can cause users or agent platforms to run shell-capable actions without an explicit trust/consent boundary, increasing the chance of unintended command execution or policy bypass.
