Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to execute local shell scripts such as `./scripts/adopt.sh` and `./scripts/interact.sh`, but the manifest does not declare corresponding permissions or clearly constrain when shell execution is allowed. This creates a trust and review gap: an agent may invoke code-capable behavior without explicit permission metadata, and the scripts are intended to use high-privilege GitHub credentials (`repo` and `workflow` scopes), increasing the risk of repository compromise or unintended account actions if the skill or its referenced scripts are modified or abused.
