Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill advertises shell-based workflows and executable scripts but does not declare any permissions, which undermines user awareness and consent around command execution. In an agent setting, hidden shell capability increases the risk of unintended local file operations, token handling, or repository modification without clear security boundaries.
