Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill instructs the agent to run local scripts under `scripts/` and perform connectivity probes, which implies shell or code-execution capability, yet no corresponding permissions are declared. This creates a mismatch between documented behavior and declared access, increasing the risk of unintended or insufficiently governed command execution in the agent runtime.
