Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 85% confidence
- Finding
- The skill instructs the agent to invoke a shell-accessible CLI (`smartchart`) but does not declare any permissions or constraints around shell execution. This creates a capability/expectation mismatch that can lead to unsafe tool use, reduced review visibility, and accidental execution of external commands in environments that treat undeclared shell access as restricted.
