Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill instructs users to run a shell script and relies on environment/config files, but it does not declare permissions for shell or environment access. That creates a trust and review gap: an agent or user may authorize the skill without realizing it can execute commands and consume sensitive configuration such as peer tokens. In this context, the skill also facilitates network communication with other agents, so undeclared execution capability increases the chance of unintended command execution or token exposure across systems.
