Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes shell-based commands (`scripts/crawlora.sh ...`) but does not declare any explicit tool restrictions such as `permissions` or `allowed-tools`. This creates an unnecessary trust gap: an agent/runtime may permit broader shell execution than the skill actually needs, increasing the chance of command misuse, argument injection through downstream composition, or unintended access beyond the documented research workflow.
