Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes shell execution via `command-tool: Bash` and `command-arg-mode: raw` but does not declare any permissions or safety boundaries. Because it performs networked actions against Twitter/X, including state-changing operations like tweeting, liking, following, and retweeting, the lack of explicit permission declarations increases the risk of unintended command execution or unauthorized external side effects.
