Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs use of shell commands (`curl`, `jq`, and `ha.sh`) that can perform live actions against a Home Assistant instance, yet no explicit permission model is declared. That creates a gap between what the skill can do and what a user or host system may expect, increasing the risk of unintended command execution against sensitive home-automation infrastructure.
