Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill explicitly instructs use of shell wrappers such as `scripts/lg_agent_exec.sh` and requires sensitive environment variables (`LG_AGENT_BASE_URL`, `LG_AGENT_TOKEN`), yet it declares no corresponding permissions boundary. That creates a capability mismatch where an agent may invoke shell-based execution and networked actions without transparent least-privilege disclosure, increasing the risk of unintended command execution or secret misuse.
