Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill directs the agent to use shell (`bash`, `curl`, temporary scripts) but does not declare that capability. Hidden execution capability reduces transparency and bypasses least-privilege review, making it easier for a supposedly simple directory lookup skill to run broader commands than users or platform policy expect.
