Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill explicitly instructs use of a shell helper script but does not declare any tool scope, permissions, or allowed-tools constraints. That creates an authorization gap where an agent may invoke shell more broadly than intended, increasing the chance of unsafe command execution or misuse of local environment secrets during skill operation.
