Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill instructs the agent to execute a shell script, but the skill declares no permissions indicating shell/code execution capability. This creates a trust and containment gap: reviewers and enforcement systems may treat the skill as lower risk than it really is, while the script can still perform network access and arbitrary shell behavior at runtime. In this context, a wallpaper-fetching skill only needs limited, explicit capabilities, so the undeclared shell execution is more dangerous because it is unnecessary to hide or omit it.
