Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill clearly instructs the agent to execute shell commands such as curl, bash, and jq against a local daemon, yet it declares no permissions or equivalent trust boundary information. That mismatch hides real execution capability from the platform and user, increasing the risk of unauthorized browser control and local script execution without appropriate review.
