Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises and demonstrates shell execution capabilities via commands like exec({ command: ... }) and extensive CLI usage, but the metadata declares no explicit permissions or guardrails. This creates a mismatch between what the skill can cause an agent to do and what reviewers or orchestrators may expect, increasing the chance of unsafe execution without policy enforcement.
