Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly guides shell-command execution and even references a helper script, but it does not declare explicit permissions or capability boundaries. In an agent framework, missing permission declarations can allow shell-capable behavior to be invoked without clear policy enforcement, increasing the chance of unsafe command execution or review blind spots.
