Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill exposes shell-command execution semantics (`time-tool <command> [args...]`) but does not declare any permissions, which creates a mismatch between documented capabilities and the security model. This is dangerous because users or orchestration layers may treat the skill as low-privilege while it can invoke arbitrary commands, enabling command execution, data access, or chaining with other tools depending on runtime constraints.
