Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 95% confidence
- Finding
- The skill advertises shell-capable behavior by instructing the agent to run a local setup script, clone a remote GitHub repository, install dependencies, and start a service, yet it declares no corresponding permissions or safety boundary. This creates a meaningful trust gap: users may invoke code execution and remote code retrieval without explicit consent or sandboxing expectations, which can lead to arbitrary local command execution through the fetched installer.
