Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill documentation indicates use of shell execution and outbound network access via a script that calls curl, but the skill declares no explicit tool scope such as permissions or allowed-tools. Without an explicit scope boundary, an agent runtime may grant broader capabilities than intended, increasing the chance of unexpected command execution or network access if the skill is invoked in a permissive environment.
