Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 89% confidence
- Finding
- The skill clearly enables shell-based network operations via curl and helper scripts, but the metadata declares only environment variables and dependencies, not any explicit permission model or execution constraints. This creates a transparency and governance gap: an agent may invoke shell/network behavior with fewer review barriers than intended, increasing the chance of unintended API use against connected repositories.
