Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill embeds executable shell workflows (`source`, credential parsing, and API helper invocation) but does not declare corresponding permissions. This creates a transparency and policy gap: an agent or user may invoke shell-capable behavior without an explicit permission boundary, increasing the chance of unexpected command execution and local file access. In this context the commands are operational rather than overtly malicious, but the undeclared capability still weakens trust and reviewability.
