Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 93% confidence
- Finding
- The skill instructs the agent to use a shell script (`./scripts/moltr.sh`) extensively, but the skill metadata does not declare shell/code-execution permissions. This creates a transparency and consent gap: an agent or platform may execute local commands and access local credential files without the user clearly understanding that code execution is required.
