Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly directs the agent to execute shell commands (`setup.sh`, permission scripts, `codearts run`) while declaring itself as a mandatory routing layer for code generation rather than transparently declaring those capabilities. Undeclared shell execution increases review blind spots and can lead to unexpected command execution in environments that rely on manifest permissions for trust decisions.
