Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill explicitly orchestrates shell execution (`bash`, `rclone`) but does not declare permissions or otherwise constrain that capability in metadata. In an agent environment, hidden or undeclared shell access increases risk because the model can trigger filesystem and network-affecting operations without an explicit trust boundary, especially for sync commands that read, write, and overwrite local data.
