Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 96% confidence
- Finding
- The skill instructs the agent to run local shell scripts directly, but the manifest does not declare corresponding permissions. This creates a hidden execution surface where user-provided company, competitor, and simulation text may be passed into shell-capable helpers without clear sandboxing or consent boundaries, increasing the risk of command execution or unsafe local actions.
