Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill invokes a shell helper (`scripts/crawlora.sh`) but does not declare any explicit tool scope or allowed-tools boundary. This increases risk because an agent may be permitted broader shell execution than necessary, making accidental misuse, command injection in surrounding orchestration, or unauthorized local actions more likely than if the skill were tightly scoped.
