Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill directs the agent to execute a bundled shell script, but the skill manifest does not declare shell/code-execution permissions. This creates a capability mismatch that can bypass operator expectations and policy controls, increasing the chance that networked script execution occurs without proper review.
