Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill includes executable shell examples (`scripts/crawlora.sh ...`) but does not declare any explicit tool scope or allowed-tools restriction. That mismatch can let an agent infer shell usage is acceptable without policy-level constraints, increasing the chance of unintended command execution or broader tool access than the skill actually needs.
