Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs the agent to generate and execute shell commands, including `wget`, `chmod`, `sh`, `nohup`, `tail`, and `ss`, but there is no declared permission model limiting shell execution. In an agent ecosystem, undeclared shell capability weakens policy enforcement and increases the chance that a user invokes privileged command execution unexpectedly.
