Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill explicitly instructs the agent to execute shell commands (`bash`, `curl`, temporary scripts) but does not declare shell permissions. This creates a trust and review gap: the runtime can perform code execution and local file manipulation beyond what a user or platform policy may expect.
