Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs the user to run a bundled shell script, but the skill metadata does not declare any tool scope or shell permission boundaries. That creates an avoidable trust gap: an agent or operator may execute local code without an explicit allowlist, making later script changes or hidden behaviors harder to govern and review.
