Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill declares operational shell capability via its required `curl` binary and explicit execution guidance, but the metadata does not expose a corresponding permission model or constrain when shell/network execution is allowed. This creates a trust gap: an agent may invoke shell-based outbound requests without clear sandboxing or user-consent boundaries, increasing the chance of unintended command execution or secret-bearing API calls.
