Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill invokes a local Node.js script via exec but does not declare any tool scope, permissions, or allowed-tools restrictions in the skill manifest. That creates an implicit trust boundary issue: an agent may be permitted to execute shell commands and access environment-derived session data without explicit authorization, increasing the chance of unintended code execution or data exposure from the local Baileys cache.
