Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill embeds shell commands that read local credential files, perform network requests, and write tokens to disk, but it declares no permissions or capability boundaries. This is dangerous because users and orchestrators cannot accurately assess or constrain what the skill can do, increasing the chance of unintended command execution and unauthorized data handling.
