Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill clearly instructs the agent/user to execute shell commands locally and over SSH, including installation to privileged paths and recovery actions, but it declares no permissions. This mismatch can bypass governance expectations and cause the skill to be invoked without the explicit shell/remote-execution safeguards that such powerful operations require.
