Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill declares installation and use of shell-capable binaries (`curl`, `jq`) but does not declare corresponding permissions or clearly scope how shell/network execution is controlled. This creates an execution-capability gap where downstream agents may run external commands and make network requests without an explicit trust or permission boundary, increasing the risk of unintended data access or exfiltration.
