Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 83% confidence
- Finding
- The skill advertises an executable `scripts/validate.sh` and an external validation backend, which introduces shell-capable behavior without any declared permission model or user-consent boundary. In an agent setting, undeclared execution capability increases the risk of unexpected command execution or network activity, especially because the skill content encourages running a local script.
