Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes shell-based capabilities through multiple executable script examples, but it does not declare explicit permissions or constraints for those operations. This weakens security transparency and can cause an agent or user to invoke filesystem and backup actions without clear consent boundaries, especially because the described operations include archiving and restoring sensitive local data.
