Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill invokes a shell script (`scripts/agent-run.sh`) but does not declare corresponding permissions/capabilities in a way that lets users or host systems clearly understand what execution rights are needed. This creates a transparency and governance gap: the skill can perform shell-based actions and network requests without an explicit permission declaration, increasing the chance of unintended execution in environments that rely on metadata for policy enforcement.
