Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs the agent to execute shell commands (`bash scripts/screenshot.sh` and `bash scripts/scrape_html.sh`) but does not declare corresponding permissions or clearly scope that capability. Undeclared execution capability is risky because users and orchestrators may not realize the skill can run local code and trigger outbound network activity through helper scripts.
