Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill instructs users to invoke a shell script (`./scripts/risk-check.sh`) but does not declare any corresponding permissions. Undeclared shell capability is risky because it can lead to execution of local commands, external network access, or unsafe handling of user-controlled inputs without the platform surfacing that capability for review and containment.
