Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill includes shell usage examples (`scripts/crawlora.sh ...`) but does not declare any explicit tool scope such as `permissions` or `allowed-tools`. That creates an authorization ambiguity where an agent or runtime may permit broader shell access than intended, increasing the risk of command execution beyond the narrowly expected API-wrapper calls. The skill’s research context is relatively low sensitivity, but undeclared shell capability still weakens containment and makes prompt or parameter injection more dangerous if this skill is reused in a less constrained environment.
