Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill invokes shell commands and browser automation but does not declare permissions or present explicit execution boundaries. This creates a trust gap: an agent may run local commands, connect to a live Chrome debugging session, and write files without the permission model making those capabilities visible to users or enforcement layers.
