Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill invokes a shell runner script but does not declare any explicit tool scope such as allowed-tools or permissions. That creates an overbroad execution surface where a caller or hosting framework may permit shell access more generally than intended, reducing isolation and making command-executing behavior harder to audit and constrain. In this context, the risk is amplified because the skill accepts user-derived query input and passes it into a script invocation flow.
