Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 86% confidence
- Finding
- The skill invokes a Node.js script via exec but does not declare any explicit tool scope such as allowed-tools or permissions. This creates an authorization gap where the runtime may permit broader capabilities than reviewers or users expect, especially since the script can inherit environment access and potentially expose local session data from the WhatsApp cache.
