Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly instructs the agent to run a bundled shell script, but it does not declare any tool restrictions or allowed-tools scope. That creates unnecessary execution latitude: an agent/runtime may permit broader shell use than intended, increasing the chance of command execution beyond the narrow API-call use case if the script or invocation is modified, substituted, or combined with untrusted input.
