Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill invokes a shell helper (`scripts/crawlora.sh`) but does not declare any `permissions` or `allowed-tools` scope. That mismatch weakens least-privilege controls and can let the agent execute shell commands without explicit review, which is risky in a skill that accepts user-influenced inputs for path/query construction. In this context the shell use appears intended for legitimate API access, but the undeclared capability still creates a real security governance gap.
