Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 92% confidence
- Finding
- The skill advertises shell execution via the recommended `python scripts/fortune_fusion.py ...` command and implies file output/chart generation, yet declares no permissions or execution boundaries. This creates a real trust and containment problem: an agent may execute local commands or write files without the user being clearly informed or the platform enforcing least-privilege constraints.
