Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs the agent to invoke a bundled shell script that performs outbound network requests, yet the skill metadata declares no permissions. This mismatch can bypass user or platform expectations about what the skill is allowed to do, increasing the risk of unintended command execution and data egress, especially because the workflow encourages direct script execution and provider auto-selection.
