Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 94% confidence
- Finding
- The skill instructs the agent to execute multiple shell commands (`gh`, `python`, shell redirection) but does not declare any permissions or execution constraints. That mismatch is a real security issue because it can cause the agent framework to run repository- and network-affecting commands without explicit user-visible authorization boundaries, especially when handling untrusted PR metadata, URLs, and logs.
