Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill explicitly instructs the agent to generate files and execute shell commands (`bash -n`, `bash`, and environment-injected runs), which are code-capable behaviors. Because the skill has no declared permissions despite requiring file read/write and shell execution, it creates a mismatch between documented trust boundaries and actual capabilities, increasing the risk of unintended command execution, file modification, or misuse of user-supplied endpoints and secrets.
