Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill exposes shell-based helper scripts and command examples but does not declare corresponding permissions, which can hide the true execution surface from users and policy engines. In an agent context, undeclared shell capability increases the chance that a host environment executes networked commands with bearer tokens or other sensitive environment variables without an explicit trust boundary.
