Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill invokes shell commands extensively (`curl`, `python3`, subshell token assignment) but does not declare corresponding permissions or clearly constrain execution. This creates a trust and review gap: an agent may gain networked shell capability and perform sensitive actions without an explicit permission boundary visible to users or policy systems.
