Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill documents executable shell and Python usage but does not declare any explicit tool scope or allowed-tools boundary. In an agent environment, this can lead to overbroad execution assumptions, making it easier for the skill to invoke shell-capable behavior without clear user or platform constraints.
