Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill instructs the agent to execute shell scripts, but the manifest does not declare permissions or clearly scope those capabilities. In this context, the undocumented shell access is significant because the skill can install software, launch services, and alter the local environment, reducing informed user consent and bypassing least-privilege expectations.
