Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 87% confidence
- Finding
- The skill explicitly instructs use of shell commands and browser/network-based workflows, but the metadata declares no permissions beyond requiring Node. That mismatch can bypass least-privilege review and cause an agent runtime to grant or attempt capabilities that were not transparently declared, increasing the risk of unintended command execution, filesystem access, and authenticated web interaction. In this context the danger is elevated because the skill operates on live marketplace listings and local files, so undeclared shell/network use can affect user data and external accounts.
