Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 90% confidence
- Finding
- The skill clearly instructs the agent to execute shell scripts, but the manifest does not declare any explicit permissions/capabilities beyond required binaries and environment variables. In an agent ecosystem, undeclared shell execution materially increases risk because users and reviewers may not realize the skill can run arbitrary local commands during banking operations.
