Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to run local shell scripts such as ./scripts/adopt.sh and ./scripts/interact.sh, but the skill metadata does not declare corresponding permissions or execution expectations. This creates a trust boundary problem: an agent may invoke shell-capable behavior without clear user consent or sandbox expectations, increasing the risk of unintended local command execution.
