Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill instructs use of a shell script (`bash scripts/rugcheck.sh ...`) but does not declare any tool restrictions such as `permissions` or `allowed-tools`. That mismatch can cause the agent framework to expose broader execution capability than intended, increasing the risk of arbitrary command execution or unsafe command composition if user-controlled input like a mint address is passed into shell context.
