Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 75% confidence
- Finding
- The skill instructs users to install and run shell commands (`pipx`, `pip`, `brew`, `apt`, virtualenv activation) but does not declare any permissions or execution expectations. In an agent ecosystem, undocumented shell capability increases risk because the agent may perform package installation or system modifications without clear consent boundaries.
