Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill advertises shell-based workflow scripts and operational capabilities but does not declare permissions or safety boundaries. In an agent environment, this can cause hidden execution capability, making it easier to perform unintended local commands or automation against sensitive infrastructure without explicit user awareness.
