Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill exposes shell-capable usage (`python ...` and direct `espeak-ng <text>`) but does not declare any `permissions` or `allowed-tools` scope in its metadata. In an agent ecosystem, missing tool scoping can let the skill be invoked with broader execution capability than intended, reducing policy enforcement and increasing the chance of unsafe command execution paths.
