Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
- The skill advertises and operationalizes shell capability via curl in metadata and execution guidance, but the static finding indicates no corresponding declared permissions. That mismatch can bypass expected trust and review boundaries, making it easier for an agent to perform networked shell actions that operators did not explicitly authorize.
