Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 82% confidence
- Finding
- The skill documentation directs the agent to invoke a local shell script, which gives the skill shell-execution capability without any declared permissions. Even though the documented purpose is benign device control, undeclared shell access expands the trust boundary and can be abused if user-controlled parameters are passed through unsafely or if the script behavior changes over time.
