Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill instructs the agent to execute a shell script, but the skill metadata does not declare any explicit permission model for shell execution beyond runtime requirements. This creates an authorization gap: a reviewer or runtime may underestimate the skill's ability to execute local commands, and the script is invoked with user-influenced values such as sender name, title, and message text. Even if the script itself may be safe, undeclared shell capability increases risk because it broadens the attack surface and hides execution power from users and policy controls.
