Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs the agent to execute shell commands (`bash scripts/dt_helper.sh`, writing scripts to `/tmp`, and running `curl`) but does not declare shell/code-execution permissions. This creates a hidden capability boundary: reviewers or policy systems may underestimate the skill’s power, while the skill can access local files, credentials, and network resources through the shell.
