Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 91% confidence
- Finding
- The skill directs the agent to execute shell scripts (`cli-state.sh`, `run-cli.sh`) but does not declare corresponding permissions or clearly surface this execution capability in a structured permission model. Hidden or undeclared shell access increases the risk that a user invoking a seemingly informational skill triggers local command execution without adequate review or sandboxing.
