Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill explicitly relies on shell execution (`curl`, shell script, cron examples) but does not declare any tool scope or allowed-tools constraints. That creates an unnecessary trust gap: an agent may execute shell-capable steps without an explicit least-privilege boundary, increasing the chance of unintended command execution or broader system access than the skill actually needs.
