Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs the agent to run bundled shell scripts and those scripts perform network access, yet the skill declares no permissions. That creates a capability/visibility mismatch: an operator or policy engine may treat the skill as lower risk than it really is, while execution still reaches shell and external network resources.
