Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill advertises shell-based usage (`./scan.sh ...`) but declares no permissions, creating a capability/permission mismatch. In agent environments, undeclared shell execution can lead to unexpected command execution paths, reduced operator visibility, and weaker policy enforcement around what the skill is allowed to do.
