Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 84% confidence
- Finding
- The skill explicitly instructs the agent to run `scripts/crawl_site.sh <domain>` as an alternative crawl path, which introduces shell execution capability that is not declared in the skill metadata or requirements. Undeclared shell use is risky because it expands the attack surface and, if the domain input is not safely handled by the script, could enable command injection or unexpected local command execution.
