Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to execute a shell command (`bash {baseDir}/scripts/scan.sh <wallet_address>`) but does not declare shell/code-execution permissions. Undeclared execution capability is dangerous because it hides the true trust boundary from the platform and reviewers, and if the script or its inputs are modified it could enable unintended command execution or external network access without explicit approval.
