Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to execute a shell script, read and write a persistent state file, and use environment-variable-controlled paths, but no permissions are declared to make those capabilities explicit. This creates a mismatch between the documented behavior and the security model, increasing the chance of unintended shell execution or filesystem access without proper review or containment.
