Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill instructs use of a shell script (`bash scripts/rugcheck.sh ...`) but does not declare any permissions for shell execution. Undeclared execution capability can bypass user/operator expectations and, if the script later includes unsafe argument handling or network/file operations, the agent may execute commands with more power than its manifest suggests. In this context the shell is used for read-oriented token lookups, which lowers severity somewhat, but the hidden capability still meaningfully increases risk.
