Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to invoke a local shell command (`python scripts/business_query.py ...`) when certain conditions are met, but the skill declares no permissions for code or shell execution. Even though the command is relatively constrained and the text warns against fabricating results, undeclared execution capability can expand the agent's attack surface and create a permission mismatch that may surprise operators or enable unsafe execution paths.
